Virsec Security Platform (VSP) leverages the patented Trusted Execution™ technology to protect high-value enterprise applications deployed in data center or on public and hybrid clouds, from highly sophisticated attacks including memory corruption, code injection, credential theft, supply chain and other sophisticated attacks. VSP effectively creates and enforces guardrails around the application as it executes. These guardrails ensure that applications only perform as intended and restrain bad actors from corrupting memory as a precursor to hijacking control of the application and subsequent stealing or destroying high-value enterprise data.

 

 

DATE OF RELEASEDATE OF RELEASE

 

2/3/2023

FIXESFIXES

 

Defect ID

Description

SUPP-435

VSP services are not starting after probe installation

SUPP-439

Out of memory error encountered for AE after Probe moved to Normal state

SUPP-544

System alerts showing disconnected probe messages everyday in CMS

SUPP-550

Pristine Mode does not work when probe is reassigned to a new Host Profile

SUPP-557

SIEM Qradar Syslog format issue causes incident

SUPP-569

Ability to export archived incidents to csv from CMS is added

SUPP-570

Ability to export Publishers and Packages list from CMS is added

SUPP-571

Website login fails after VSP instrumentation for .NET application

SUPP-576

Unknown error encountered while managing 2.5.0 Allowlists

SUPP-582

Vulnerabilities reported in VSP-Sidecar scan

SUPP-628

LFI incidents are reported for requests that match the exclusions defined in LFI profile

SUPP-659

Events do not reach vRule Engine

Table – VSP 2.4.8 Fixes 

KNOWN ISSUESKNOWN ISSUES

 

Category

Description

Known Issue/ Caveat

Host Monitoring

Windows library issue

In Windows, VSP host monitoring does not suspend already running processes that have non-whitelisted libraries loaded into it

Known Issue

Linux HMM agent limitation

In Linux, VSP host monitoring injects its own HMM agent into every running process. The HMM agent expects a specific version of glibc. If the application loads its own custom glibc version that is not compatible with the HMM agent, the HMM agent may not load correctly causing some application issues

Limitation

Windows application execution inconsistency

In Windows, an application can be started with or without its .exe extension. Since VSP host monitoring analyzes the commandline as is, running python.exe vs python may result in different detections

Limitation

Table – Known Issues