Jul 28, 2021
This release includes new and updated policy content and several Security Console interface and scanning fixes.
New
Customer Requested
- New Cisco NX-OS policy: We added a new Defense Information Systems Agency (DISA) policy that provides a STIG benchmark for Cisco NX-OS Layer 2 Switch.
Improved
- Updated Microsoft Windows policy: We updated our Center for Internet Security (CIS) Microsoft Windows 10 Enterprise Release 1511 policy to version 1.1.1.
Fixed
- We fixed an issue that could delay the updating of asset, vulnerability, and risk count data in asset groups due to calculation conflicts if a large number of scans completed at the same time.
- We updated our vulnerability checks for HP-UX to account for patch supersedence in order to avoid false positive results.
- We fixed an issue in some CIS Unix policies where certain rules were causing scans to hang.
- We updated our banner-matching logic to improve the accuracy of MariaDB service fingerprints.
- We updated our content generation process to reduce false positives and negatives that could result for Cisco hardware checks.
- We fixed an issue that caused 32-bit installations of Azul Zulu OpenJDK versions to be misidentified as Oracle JDK, leading to false positives.
- We updated our HP Systems Insight Manager fingerprinting process to correctly capture hotfix versions.
- We fixed an issue with our Microsoft SQL fingerprinting process that prevented some versions of Microsoft SQL from being identified correctly.
- The links inside the help tooltip next to the SQL Query Export query execution field in the Security Console will now generate sample queries when clicked and route the user to relevant documentation as intended.
- Assets in your Security Console that belong to more than one site have a Global link in the Site column of the Scanned table on the Assets page that produces a tooltip with individual site links. We fixed an issue that prevented these site links from directing the user to the corresponding site detail pages when clicked.
- When looking at scheduled scans in your calendar, clicking a scheduled scan produces a tooltip that allows you to view the site associated with the scan. We fixed an issue that prevented these View site links from working.