まっちゃだいふくの日記

セキュリティのこと、ITの気になった記事をリンクしています。

Deep Security Agent 20.0.0-2593 (DS 20 LTS Update 2021-07-01)Ubuntu18.04でFIPSモード(暗号スイートをUS federalベースに限定するモード)をサポート、その他修正対応

Deep Security Linux Agent - 20.0.0-2593 (20 LTS Update 2021-07-01)

Deep Security Agent - 20.0.0-2593 (20 LTS Update 2021-07-01)
Release date: July 01, 2021
Build number: 20.0.0-2593

New feature

FIPS mode on Ubuntu 18.04: Deep Security Agent (version 20.0.0-2593+) now supports FIPS mode for Ubuntu 18.04.

Resolved issues

  • Integrity Monitoring alerts sometimes triggered but did not appear in the Events & Reports tab. 04266346/SEG-103731/DS-62992
  • Deep Security Agent sometimes triggered multiple "Log Inspection Engine Initialized" alerts due to an agent-manager communication issue. SF03968169/SEG-95731/DS-60840
  • The MQTT connection sometimes went offline when Deep Security Agent had Activity Monitoring enabled. SF04216172/SEG-101691/DS-63458
  • Application Control was detecting multiple "Application Control Software Changes Detected" events due to '.tmp" files being generated by PowerShell. C1WS-1608

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. VRTS-5850/DS-54705

  • CVSS score: 4.4
  • Severity: Medium
What's new in Deep Security Agent? | Deep Security

Deep Security Windows Agent - 20.0.0-2593 (20 LTS Update 2021-07-01)

Deep Security Agent - 20.0.0-2593 (20 LTS Update 2021-07-01)
Release date: July 01, 2021
Build number: 20.0.0-2593

Resolved issues

  • Deep Security Agent sometimes triggered multiple "Log Inspection Engine Initialized" alerts due to an agent-manager communication issue. SF03968169/SEG-95731/DS-60840
  • Anti-Malware sometimes went offline after enabling Application Control on Deep Security Agent. SF04532752/SEG-110572/DS-63406
  • Application Control was detecting multiple "Application Control Software Changes Detected" events due to '.tmp" files being generated by PowerShell. C1WS-1608
  • Citrix Virtual App or Desktop users sometimes encountered a grey screen (with error code 1003/1005) when Anti-Malware was enabled for Deep Security Agent. DS-64318
  • Anti-Malware sometimes caused high system CPU usage when the Windows WMI service accessed files repeatedly. SEG-109271/DSSEG-6983

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. VRTS-5850/DS-54705

  • CVSS score: 4.4
  • Severity: Medium
What's new in Deep Security Agent? | Deep Security

Deep Security UNIX Agent - 20.0.0-2593 (20 LTS Update 2021-07-01)

Deep Security Agent - 20.0.0-2593 (20 LTS Update 2021-07-01)
Release date: July 01, 2021
Build number: 20.0.0-2593

Resolved issues

  • Deep Security Agent sometimes triggered multiple "Log Inspection Engine Initialized" alerts due to an agent-manager communication issue. SF03968169/SEG-95731/DS-60840
  • Integrity Monitoring alerts sometimes triggered but did not appear in the Events & Reports tab. 04266346/SEG-103731/DS-62992
  • Deep Security Agent failed to detect the correct platform under some configurations. 03804296/SEG-90864/DS-57809
  • Application Control was detecting multiple "Application Control Software Changes Detected" events due to '.tmp" files being generated by PowerShell. C1WS-1608

Security updates

Security updates are included in this release. For more information about how we protect against vulnerabilities, visit Vulnerability Responses. Please note, in line with responsible disclosure practices, CVE details will only be made available for select security updates once patches have been made available for all impacted releases. VRTS-5850/DS-54705

  • CVSS score: 4.4
  • Severity: Medium
What's new in Deep Security Agent? | Deep Security