{"Up2Date": {"bugs": ["NC-81131 [Reporting] Last access time is not generated when there is user present with username having xss payload", "NC-94019/ NC-100737 [Wireless] Inbound traffic for hosts connected on Wi-Fi SSID on Separate zone is dropped by firewall rule ID 0, and outbound traffic may experience slowness", "NC-100681 [IPS Engine] Increase in snort memory with ATP pattern updates", "NC-100971 [IPsec] Migration gets failed from v19.0 GA to v19.0 MR-1", "NC-100679 [CDB-CFR, Reporting] 'INSERT INTO available_login_eventv6%' error in postgres.log causing conf partition to rise", "NC-89091 [API Framework] Resolved multiple post-auth SQLi vulnerabilities in Webadmin (CVE-2022-1807)", "NC-83114 [Authentication] Web Authentication does not work in HA mode while AUX node is rebooting", "NC-85151 [Authentication] Opcode failing getting \"Failed because of Invalid Parameters\" resulting error in Full Sync", "NC-84142 [Backup-Restore] Unable to delete vlan interface", "NC-85547 [CaptivePortal] Sign in message and Logout Option not appearing with custom captive portal", "NC-80305 [Certificates] Though CA is not available on pfx file, CA upload opcode gets called", "NC-81430 [CM, UI Framework] Userportal host injection reported", "NC-83405 [Core Utils] Inconsistency with Security Audit Reports (SAR)", "NC-84231 [Core Utils] Receiving a duplicate copy of the same executive schedule reports. ", "NC-89218 [Core Utils] Resolved post-auth shell injection in Webadmin via OpenSSL (CVE-2022-1292)", "NC-82972 [CSC] Appliance went in a hang state.", "NC-92745 [DNS] kdump : stack guard page was hit", "NC-83419 [Email] Inbound emails not receiving with SMTP scanning enabled", "NC-85346 [Email] Smarthost authentication failed in server_plain authenticator: nsgenc decryption failed", "NC-87240 [Email] Avira Engine error with axpx files", "NC-90702 [Email] SASI detection problems when too many hits are returned", "NC-92840 [Email] RCA for email not received with an error \"smtp_check_forward_reply: response arrived without any command\"", "NC-93380 [Email] Antispam not working after upgrade to SFOS 18.5.3", "NC-81939 [Firewall] FW not reflecting daylight savings time correctly", "NC-83734 [Firewall] Randomly inbound emails are getting dropped in HA load balancing with SMTP Scanning enabled", "NC-86093 [Firewall] Duplicate firewall rule group  Similar as NC-67119", "NC-89076 [Firewall, VFP-Firewall] Unable to access Website www.radix.ad.jp on the environment Tagged VLAN + DPI configured\u00a0", "NC-89162 [Firewall] AutoReboot  0010:queued_spin_lock_slowpath+0x148/0x170 ", "NC-90024 [Firewall] Backup restore/migration fails due when multiple local ACL rules are configured", "NC-91295 [Firewall] Zones tab showing blank after deleting zone created on second page", "NC-86819 [Firmware Management, Licensing] AWS instance stuck while booting it ", "NC-88207 [Firmware Management] Firmware update fails when space is used in filename", "NC-94291 [Firmware Management] small var partition created for VM image using aux disk", "NC-82225 [HA] Unable to establish the HA correctly on fiber ports", "NC-86451 [IPS-DAQ-NSE] Unable access web server via XG with SSL/TLS inspection error \"Dropped due to TLS internal error\" occurred.", "NC-92131 [IPS-DAQ-NSE] Not able to upload a large file with SSL/TLS Inspection enabled in do-not-decrypt mode", "NC-79128 [IPsec] Memory increase to 90% over 20-25 days", "NC-79319 [IPsec] Add a hint to IPSEC", "NC-79359 [IPsec] IPsec Profiles - Using AES256GMAC can show invalid configuration", "NC-81207 [IPsec] Firewall GUI : Getting error while updating any VPN Tunnel config", "NC-81944 [IPsec] WWAN is not connecting after random disconnect event if xfrm interface is created on WWAN", "NC-83445 [IPsec] Constant IPSec VPN Flapping - Pushed via Central SD-WAN Orchestration", "NC-85383 [IPsec] Unable to connect ipsec remote access due to invalid .scx file", "NC-88404 [IPsec] Tunnel not auto came up after reboot happened in HA appliance", "NC-88903 [Localization] German Menu is broken", "NC-89996 [Logging] IPS policy redirection from Log viewer", "NC-90566 [NFP-Firewall] Traffic not traversing XGS firewall under specific configuration", "NC-76071 [RED] XGS-2100- Interface does not have any IP address when restored -Same HW/Same FW", "NC-90839 [RED] Red Interface disappear while changing the DHCP server configuration ", "NC-81131 [Reporting] Last access time is not generated when there is user present with username having xss payload", "NC-94337 [Reporting] Migration failure to v19.0GA - Failed due to MaxNoTables24hr_tls already exists", "NC-86652 [SDWAN Routing] TFTP traffic do not follow SD-WAN routing", "NC-86690 [SDWAN Routing] SD-WAN FTP Proxy Traffic not working with Transparent Proxy", "NC-90203 [SDWAN Routing] SD WAN Rule update fails, if rule-name has extra space", "NC-93720 [SecurityHeartbeat] delay-missing-heartbeat-detection not synched on AUX", "NC-85423 [SNMP] Kernel crash on XG125 with SNMP high memory consumption", "NC-83469 [SSLVPN] Dashboard does not reflect the remote user\u2019s detail", "NC-87596 [SSLVPN] SSL VPN not working \u2013 (Site to Site and Remote Access) ", "NC-88483 [SSLVPN] CVE: 2022-0547 openvpn deferred auth vulnerability", "NC-93919 [SSLVPN] SecurityHeartbeat_over_VPN object removed from SSL VPN policy after an SSL VPN global config change", "NC-93689 [Up2Date Client] Cosmetic Issue with SASI Pattern after Firmware Downgrade", "NC-84146 [WAF] Warning about subject alternate not being part of domain", "NC-84604 [Wireless] Unable to restore backup from SG230 to XGS2300 due to access point database issue", "NC-87659 [Wireless] Legacy AP roaming key decryption is failing when fast transition is enable", "NC-90684 [Wireless] Multiple APX 320s Not Registering With XG Firewall (Not Coming in Pending List)", "NC-91300 [XGS BSP] npu_version (among other things) missing from telemetery- oddly high number of missing entries"], "news": ["Maintenance Release", ".", "[SSLVPN] Static IP lease support for SSL-VPN remote access users. Now supports mapping of RA users with static IP to improve user traceability, monitoring, and visibility. This also includes static IP lease from the external Radius server.", "[IPsec VPN] Added default IPsec S2S IKEv2 policies for improved HO \u2013 BO tunnels. This eliminates manual fine tuning required for HO and BO policies like re-key interval, DPD action and key negotiation retries. This helps eliminate re-key collisions and DPD (dead peer detection) related issues.", "[IPsec VPN] Changed defaults to prevent flapping of non-tcp (VoIP, RDP, Skype, Zoom, UDP, etc) connections at the time of tunnel up/down or tunnel flapping. Disabled 'vpn conn-remove-tunnel-up' and enabled 'vpn conn-remove-on-failover' for new configurations. The change does not impact existing deployments after firmware upgrade or migration.", "[RED] Supports multiple DHCP server for RED interface.", "[Licensing] A valid support subscription will become mandatory for firmware upgrades after three free upgrades. This does NOT impact the trial license, home use license or firmware upgrades from the install wizard. Please refer to the online help for further information.", "[SD-WAN] rule-id and index column are added on SD-WAN profile manage page for easier troubleshooting.", "[Sync security] Improved firewall management experience from Sophos Central in the environment with thousands of end point certificates used for sync security heartbeat.", "[Email] Added a capability to report a spam email as a False Positive from the quarantine release screen.", "[Malware] Upgrade of malware scan engines and associated components to full 64-bit operation to ensure optimum performance and future support.", "[Sophos Assistant] Added UI option to opt out from Sophos Assist"], "version": "SFOS 19.0.1 MR1-Build365"}}
