Genian NAC 5.0.50 Release Notes (2022-12-05)

Last Updated: 2023-07-20

Security Vulnerability

Revision Key Components Description Affects Versions CVSS Score
114720 GN-26368 WebUI Vulnerability where an administrator's API key is exposed to other administrators   5.3
114214 GN-26392 WebUI Vulnerability that allows unprivileged administrators to download debug logs   2.9
113219 GN-26460 Windows Agent A vulnerability that allows an ordinary user to obtain PC administrator rights via an agent 5.0.0, 6.0.0 4.6
112785 GN-26286 WebUI An issue where Google OTP 2-step verification can pass 2-step verification by receiving a new security key   6.5
111886 GN-26150 WebUI Tomcat version upgrade (9.0.68 -> 9.0.72, 8.5.78 -> 8.5.86)    
111844 GN-26205 Database MySQL version upgrade 5.7.40 -> 5.7.41    
111681 GN-25869 CWP A problem where only an account (ID) is authenticated when CWP is authenticated using the agent user authentication menu when the IP management message is first on 6.0.3, 5.0.46 3.4
111338 GN-26000 MySQL MySQL version upgrade 5.7.33 -> 5.7.40    
111257 GN-26062 Center, macOS Agent, Sensor, Windows Agent OpenSSL 1.1.1t upgrade - Passing random pointers to memcmp calls can read memory contents or cause denial of service   7.4
111018 GN-25982 WebUI CSP and HSTS headers added to WebUI Response Headers    
110496 GN-25875 Windows Agent A problem where agents have high privileges when running a web browser 4.0.0, 5.0.0, 6.0.0 3.3
110418 GN-25811 IPMGMT A problem where you can log in with only a user ID via frontpage in the IP application system   4.9
110230 GN-25925 IPMGMT, WebUI IP Application System > IP Application Screen XSS Possible Problems   5.4
110145 GN-25740 WebUI Issues where XSS is possible in Audit > Logs > Log search bar   5.6
109992 GN-25847 WebUI Added a re-authentication procedure when accessing the user information modification page on the CWP screen   4.2
109563 GN-26051 WebUI 5.0 WebUI lib vulnerability check    
109563 GN-25250 WebUI Possible problems with XSS when/is appended after the HTML Tag string   4.9
109563 GN-23677 Center, Sensor Administrator approval system to enhance security when registering sensor policy servers   7.9

New Features and Improvements

Revision Key Components Description Affects Versions
118280 GN-26838 Ubuntu(Debian) [General-purpose OS] ICMP Timestamp support removed  
117757 GN-26702 WebUI A function that outputs a warning when external access is permitted from the policy server  
117448 GN-26769 Linux Agent Linux Agent, development of distribution plug-ins based on Sigstore electronic signatures  
116767 GN-26826 geniup A problem where a disk runs out when performing geniup on a UEFI system  
116532 GN-26705 Center Electronic signature verification of update server distribution data via SLSA  
116395 GN-26844 Center, Sensor Display whether the sensor can be accessed externally in sensor information (public IP)  
115885 GN-26786 Center Electronic signature verification for WSUSSCN2.CAB received from the update server  
114255 GN-26328 WebUI Improved to include node group names when downloading node groups in Excel  
112249 GN-26255 WebUI Increase OTP input length to 32 characters  
111632 GN-26135 macOS Agent Added macOS file distribution options and improved logic related to file execution 5.0.35
111187 GN-25994 macOS Agent Adding USB device information to the macOS hardware information collection plug-in  
110538 GN-25579 Center Node snapshot cleanup function missing  
110499 GN-25865 Windows Agent Improvement of center load problems caused by infinite repetitive transmission in a short time when transmission of information collected from agents fails 4.0.0, 5.0.0, 6.0.0
109979 GN-25656 RADIUSD [RADIUS] Changed to output detailed failure audit logs when linking AD authentication  
109641 GN-25446 Linux Agent Linux Agent develops additional collection function for Sophos Linux vaccine information  
109563 GN-26171 CWP Improved so that the administrator's ID is not displayed in CWP announcements  
109563 GN-25601 WebUI An issue where application information is disabled on the IP usage application modification screen  
109563 GN-25496 macOS Agent Change the check cycle to enable automatic macOS agent update load balancing  
109563 GN-25494 Windows Agent Modified so that the password validation window can automatically close when detecting a password change  
109563 GN-25479 WebUI Remove the html syntax of the device usage application processing notification message  
109563 GN-25477 macOS Agent Duplicate processing of popup messages when using the wireless LAN control plug-in in macOS sleep mode  
109563 GN-25457 WebUI Send an 'instance message' via REST API  
109563 GN-25416 Linux Agent Handling exceptions for using different time zones on the Linux Agent and Policy Server  
109563 GN-25388 Windows Agent Adding help to the Wireless LAN Control Plug-in for the "Allowed SSID-Regular" option  
109563 GN-25322 WebUI Add each column to the user management view when the last authentication was deactivated  
109563 GN-25316 GNOS "Invalid DHCP Server Collection Information" - Always add output options to the relevant risk audit log  
109563 GN-25273 GenianOS [General-purpose OS] Improved to allow custom use of apache2 settings 6.0.3
109563 GN-25266 Windows Agent Show whether to use an empty password in the debug log when starting the password verification plugin  
109563 GN-25231 WebUI Fixed an issue where loading takes a long time when clicking on the MAC address condition in node group conditions  
109563 GN-25223 Linux Agent Linux Agent adds web browser integration downloaded from snap when connecting to a web browser via a tray icon  
109563 GN-25212 WebUI Improved output of the period (date and time input format) input item on the CWP new user registration screen  
109563 GN-25205 WebUI Node Details - Improved output of recent execution results on the Operating System Update Information tab  
109563 GN-25191 WebUI Provided so that the changed status can be checked with an image icon when 'agent service is stopped'  
109563 GN-25189 CLI/gnlogin Improved so that mgmt-local-port is applied when entering the mgmt-port CLI 5.0.44, 6.0.2
109563 GN-25161 Center Port bounce processing when the Switch Port VLAN is changed through the control policy  
109563 GN-25096 Center Improved so that RADIUS MAC authentication node group checks can be compared using Calling-Station-Id  
109563 GN-24841 Linux Agent, WebUI, Windows Agent Added the ability to delete the content set in the sub-item when changing the settings in the Windows Firewall Control plug-in's custom rules to “All”  
109563 GN-24820 WebUI Audit > Log data usage display function added to the log screen  
109563 GN-23573 Windows Agent Change the check cycle to enable automatic agent update load balancing  
107294 GN-25095 Linux Agent Linux Agent develops file distribution action plug-in  

Issues Fixed

Revision Key Components Description Affects Versions
117427 GN-26213 WebUI An issue where an option value that does not change when assigning a node group after creating a node policy appears to have changed 5.0.44
117233 GN-26852 Center, Genian Syncer An issue where Mobilebrowser data cannot be updated when uploading Genie data via Syncer, and an issue where CVE data versions cannot be updated 4.1.0
117182 GN-26770 Center, Sensor [General-purpose OS] A problem where the sensor does not work as a distribution server 5.0.29
116853 GN-26839 Center, Sensor Policy Server/Sensor Memory Rick (Genie Update and Node Scan (https)) issues 4.0.14
116616 GN-26779 WebUI A problem where a warning message is output even when the log server (elasticsearch) is in a normal state 5.0.23
116581 GN-26758 Windows Agent If the agent runs on a local system, the Store app fails to be deleted through the program removal plug-in 5.0.42, 6.0.0
116343 GN-26623 WebUI A problem where the IP expiration time is not displayed when exporting to Excel when the node management view is an IP management view 5.0.50
115785 GN-26749 ElasticSearch [General-purpose OS] An issue where ES does not run properly intermittently because communication with Elastic is blocked by the Iptables policy 5.0.31
115639 GN-26727 Sensor [General-purpose OS] A problem where a DHCP server that assigns the same DNS as the sensor is detected as an abnormal DHCP server  
115493 GN-25887 WebUI Subcategories are not displayed in the multi-level category structure within the status filter node group 5.0.42, 5.0.45, 6.0.2
115289 GN-26719 WebUI An issue where when creating a time object from the Policy > Object > Time menu causes the date to be stored incorrectly if the System Timezone and Administrator Timezone are different 5.0.34
115122 GN-26428 Center A problem that may fail depending on the OS type when upgrading the deb image through the console UI 5.0.42, 6.0.12
115022 GN-26607 GenianOS The problem of not being able to connect to the Genian Monitor program from the IP that allows access to the management WEBUI 5.0.42, 5.0.50, 5.0.53, 6.0.13
114668 GN-25626 WebUI An issue where regular users are searched even when the visitor's email approval target is an administrator 4.0.M8
114312 GN-26597 WebUI A problem where query reports are not generated when the DB/Log server is separated 5.0.37
114300 GN-26532 WebUI Fixed an issue where the number of NIC vendor status did not match  
114265 GN-26609 WebUI An error occurs when registering a node using the node addition field (user selector-mapping column name) 5.0.42, 5.0.50, 6.0.11
114197 GN-26440 WebUI There is no change in the tag, but the node details are also updated and processed when the node details are modified 5.0.22, 6.0.4
114197 GN-26425 WebUI A problem where the data does not include the parent department when selecting the user department in the node group condition 5.0.35
114153 GN-26280 Center A problem where a multi-sensor device is registered in an approved state when re-registered after deleting it 6.0.8, 5.0.50
114066 GN-26566 WebUI An issue where the changed information was updated and not displayed when the tab was moved after updating the node information 5.0.50
113986 GN-26476 WebUI Correction of errors on the execution results status page for each action 5.0.50
113769 GN-25776 Center Improved so that password change expiration notifications are not displayed for users without a password and synchronized users (READ ONLY) 4.0.18
113594 GN-26319 WebUI A problem where when clicking on the management device name on the audit log screen, node management is not retrieved and all are output 5.0.38
113556 GN-26448 WebUI An error where policy server information is not output from the system list after installing the Compose method 5.0.6
113541 GN-26540 Windows Agent Windows 11 is incorrectly displayed as Windows 10 when selecting the plug-in 'Applicable OS' in the English management console. 5.0.42, 6.0.0
113486 GN-26267 WebUI An issue where today's audit log is not output from Audit > Logs before 9:00 KST 4.0.17
113400 GN-26357 WebUI A problem where the old version of the detailed screen is displayed when returning to the basic status from the target node list on the new node group detail screen 5.0.35
113357 GN-26322 macOS Agent An issue where CPU usage increases when receiving macOS notification messages 5.0.27
113343 GN-26446 Center An issue where the center daemon's fd increases when the LDAP connection fails 5.0.41, 4.0.145, 6.0.0
113322 GN-26444 WebUI Symptoms of not being able to search for Hangul in the software settings window under node group conditions 5.0.35
113136 GN-26130 macOS Agent Crash issue when using the macOS hardware information collection plug-in 5.0.38
113084 GN-26040 WebUI Change node management An issue where the administrator confirmation function does not work when selecting all nodes 5.0.26
113044 GN-26414 Windows Agent A problem where the fixed option in the password verification window is periodically placed in the center of the screen even when the fixed option is off 5.0.42, 6.0.12, 5.0.53
113024 GN-26433 Sensor An issue where sensor communication may not be possible due to an incorrect IP rule being created when adding a gateway IP 5.0.42
112771 GN-26160 Authsync, Center A problem that may fail when downloading CSV and synchronizing user information 5.0.0
112754 GN-26385 Packaging C30G and C50G equipment monitor output problems 5.0.44, 6.0.1
112674 GN-26259 ElasticSearch Error displaying shard information in the Elasticsearch management tool on the Advance page 5.0.17
112643 GN-26223 WebUI A problem where only 50 tags are output when assigning tags on the node detail screen 5.0.22
112598 GN-26242 WebUI An issue where agents installed on cloud OS (Linux) are displayed as a Windows icon in the node list in the management console 6.0.8, 5.0.50
112511 GN-26227 Center [General-purpose OS] An INVALID COMMON NAME certificate error occurs because the server certificate does not have Subject Alternative Names 5.0.23
112389 GN-26208 WebUI An issue where XSS detection logs are left when entering a search term containing < characters in the search box 6.0.7, 5.0.50, 4.0.152
112371 GN-26178 WebUI An issue where an XSS discovery log is left due to -> included in the detailed audit log message 6.0.7, 5.0.50, 4.0.152
112122 GN-25936 WebUI A problem where node task commands that work regardless of management role permission settings do not work 5.0.44, 6.0.1
112106 GN-26219 WebUI An issue where an error occurs when copying a policy if the action has a label 4.0.113, 5.0.10
112065 GN-26170 WebUI A problem where adding/deleting components of the CWP design template in the English management console does not work properly 5.0.48, 6.0.7
111954 GN-26200 Center An issue where the CVE list is not updated in the latest versions of ZTNA and NAC 5.0.50, 6.0.12, 5.0.53
111828 GN-26188 IPMGMT A problem where temporary users cannot automatically log in to the IP application system 5.0.50, 4.0.153, 6.0.11
111738 GN-25998 Windows Agent (Password Verification Plug-in) An issue reported because the account's password change time is constantly changing 4.0.M5, 5.0.0, 6.0.0
111729 GN-25565 Center Center daemon abnormally shuts down when sending Syslog TLS 4.1.M7
111670 GN-26175 Center The phenomenon of continuing to download GPDB from cloud services using GDPI 5.0.41
111620 GN-26106 Windows Agent A problem where sharing is not disabled when setting the sharing allowance time in network shared folder control 5.0.42, 5.0.50, 6.0.11
111587 GN-26137 WebUI An issue where the CWP page preview screen is not visible on the CWP design template settings page 5.0.42, 5.0.50, 6.0.11
111559 GN-26161 GenianOS Fix sshd restart error in procmond 5.0.23
111463 GN-26028 Windows Agent Fixed an issue where forced termination of a process did not work when there were multiple action policies to forcibly terminate the process 5.0.25
111171 GN-26068 WebUI [5.0] An issue where clicking on an automatically generated dashboard report does not download and goes to a blank screen 5.0.50
111067 GN-26063 IPMGMT An issue where the automatic login function for IP usage applications does not work in CWP 5.0.50, 4.0.153, 6.0.11
111039 GN-26008 WebUI An issue where the policy copy function does not work on the node group details screen 5.0.31
110998 GN-26047 WebUI [4.0/5.0] Fixed an issue where the dashboard > Sensor Map was not displayed 5.0.42
110983 GN-26029 CLOUD Cloud NAC user information not syncing problem 6.0.3, 5.0.50
110975 GN-26045 CLOUD An issue where the GDPI API is not set to use when creating a new Cloud Site 5.0.50, 6.0.10
110914 GN-25900 Linux Agent A problem where the number of receiving policies from the server increases during long-term use of the Linux Agent 5.0.41, 6.0.0
110851 GN-25832 WebUI An issue where the management console session time changes when the PC time is changed 5.0.48, 6.0.7
110794 GN-26018 WebUI An error occurred during approval on the detailed view screen of the new/return application form 5.0.49, 6.0.8
110786 GN-25995 WebUI A problem where the ban on deleting a node cannot be applied when registering a node in IP address management 5.0.40
110781 GN-25964 Windows Agent An issue where the execution option after authentication disappears after upgrading the agent authentication window 5.0.42, 6.0.3, 5.0.46
110530 GN-25893 WebUI 5.0 A problem where the node target task command for task selection cannot be executed after selecting a node in node details. 5.0.44, 6.0.1
110443 GN-25880 Center [General-purpose OS] Problem with not being able to output favicons 5.0.37
110351 GN-25931 CWP When using Domain with On Premise, authentication is not possible because an authentication request occurs with an IP address during SAML authentication 5.0.48
110323 GN-25888 Center Symptoms of not being able to issue a Google verification code when synchronizing information with the mail server 5.0.16, 6.0.0
110210 GN-25903 macOS Agent An issue where the agent malfunctions when the macOS file distribution plug-in file is not uploaded 5.0.31, 6.0.0
110174 GN-25796 Center A problem where the node type changes even when a node type is specified when registering a new node by an agent 5.0.33
110155 GN-25885 Sensor A problem where switch port information cannot be collected 6.0.4, 5.0.47
110062 GN-25863 WebUI A problem where the node management search term does not work if is in the search term 5.0.42, 5.0.49, 6.0.8
110024 GN-25905 WebUI [5.0] Fix incorrect node list links in widgets and status screens 5.0.48
109975 GN-25868 Center An issue where no node (agent) up/down logs are left intermittently 5.0.49
109950 GN-25699 WebUI Problems where the filter results of the agent action in Status Filter differ from the detailed query history, and Excel cannot be downloaded 6.0.4, 5.0.48
109755 GN-25818 WebUI When uploading an agent file, an out of memory error occurs on a device with low memory and cannot be uploaded 6.0.8, 5.0.50, 4.0.152
109725 GN-25750 Windows Agent A problem where a web browser opens with an incorrect URL in the authentication window 5.0.0, 4.0.123
109563 GN-26655 WebUI An error page occurred when exporting node management to Excel in the Compose version 5.0.48, 6.0.6
109563 GN-25979 Center A problem where the policy application queue does not work properly when the RADIUS policy is changed multiple times 5.0.23
109563 GN-25978 WebUI A problem where the password length error is displayed even though the password was not changed when editing on the switch detail screen 5.0.17
109563 GN-25864 Genian Mobile The problem with Genian NAC Monitor not being able to connect to the center 5.0.49, 6.0.9
109563 GN-25815 WebUI A problem where the approval/rejection popup for a new IP application is active and the approval/rejection popup is enabled, the problem is that it is in a waiting state when approved/rejected 4.1.3
109563 GN-25745 Linux Agent Problems with "Distribute Files" Plug-in not executing files with Root permissions 6.0.8, 5.0.50
109563 GN-25734 Windows Agent IE is displayed when clicking a hyperlink in an agent notification message 6.0.4, 5.0.47
109563 GN-25652 WebUI When moving by clicking on the platform quantity in the CVE status widget on the dashboard, an error occurred when clicking the list button 5.0.43, 6.0.0
109563 GN-25642 WebUI An issue where the improved node group condition setting UI does not appear in version 5.0 5.0.49
109563 GN-25574 macOS Agent An issue where message-related IDs within the macOS agent cannot be imported properly 5.0.50, 6.0.9
109563 GN-25559 Windows Agent The problem of not being able to connect due to incorrect registration of the Hangul SSID profile through the wireless connection manager 4.0.5, 5.0.0, 6.0.0
109563 GN-25549 dbmigration RADIUS Accounting does not work after creating a CLOUD customer site 5.0.33
109563 GN-25498 macOS Agent An issue where the screensaver option in the macOS Appearance and Personalization plug-in doesn't apply 5.0.15, 5.0.45, 6.0.2
109563 GN-25462 Genian Monitor Web page error display issue when clicking on details in Genian Monitor for Windows 5.0.19, 6.0.0
109563 GN-25443 Center A problem where the certificate expiration log remains based on the device certificate even when using a custom certificate 5.0.0
109563 GN-25439 Center An issue where the agent installation node's platform changes to Unknown when manually updating GPDB  
109563 GN-25428 Ubuntu(Debian) [General-purpose OS] Problem of not being able to upload and download agent installation files after restoring agent files 5.0.23, 6.0.0
109563 GN-25418 GenianOS [General-purpose OS] An issue where the file export (Excel Export) function does not work  
109563 GN-25399 Center, Database An issue where the number of nodes in the Windows update status is displayed incorrectly when assigning a Windows Update action label 4.0.113, 5.0.10
109563 GN-25390 Sensor An issue where permissions do not work properly when using FQDN network objects 5.0.27
109563 GN-25381 Center, CLOUD Symptoms of a certificate not being reissued with the Reissue Certificate button in the CLOUD version 5.0.45, 6.0.2
109563 GN-25364 WebUI A problem where visible processing of child settings is not processed properly when the CONF On/Off button is set as the parent 5.0.16
109563 GN-25350 WebUI An issue where a logged-in administrator UI session ends after approving/rejecting an email for a new IP application 4.1.0
109563 GN-25345 Center [General-purpose OS] An issue where the automatic sensor upgrade function does not work when upgrading the policy server 5.0.43, 6.0.0
109563 GN-25340 macOS Agent An issue where the macOS operating system information collection plug-in fails to obtain the installation date 6.0.4, 5.0.47
109563 GN-25339 WebUI The phenomenon of switching to the analysis chart page when the refresh button is clicked while the log search and search filters are modified 5.0.22
109563 GN-25319 WebUI An error page is displayed when multiple nodeType conditions are entered and queried in the node list 5.0.42, 5.0.45, 6.0.2
109563 GN-25317 Center A problem where the time object is not released from the node group even after the end time of the node group condition 4.1.3
109563 GN-25289 macOS Agent macOS Device Control plug-in operation errors and log improvements 6.0.3, 5.0.46
109563 GN-25279 WebUI A problem where the results are incorrectly displayed in the node type widget from the node list moved to links of some node types 5.0.43, 6.0.0
109563 GN-25271 Center Modified so that only the linked interface is checked when applying the primary/secondary DNS condition policy 5.0.0
109563 GN-25259 Windows Agent A problem where the result of performing the previous action remains even if the node policy is changed to OFF or not to use the agent 5.0.0, 6.0.0
109563 GN-25253 Windows Agent After blocking device control, it is output in the audit log in the form of “ID = number” and modified to the policy name 5.0.25, 6.0.0
109563 GN-25238 WebUI A problem where there is no X button in the department search pop-up in the node group condition addition UI, and the cancel button is not displayed in the second department search pop-up when there is no department information 5.0.20
109563 GN-25219 Center [General-purpose OS] An issue where master files are not synchronized to the Slave in an HA redundant configuration  
109563 GN-25216 WebUI A problem where a file cannot be uploaded properly when uploading a file via the REST API 5.0.42, 5.0.45, 6.0.2
109563 GN-25159 WebUI An issue where all header lists set in URL calls are not deleted 5.0.15
109563 GN-25152 IPMGMT Page error when applying for IP use while violating the IP management policy 5.0.11
109563 GN-25147 WebUI An issue where all of the default node groups have been updated, but it may show that there is an updatable quantity 5.0.27
109563 GN-25144 Center A problem where the server connection fails if the authentication-linked server address contains a space  
109563 GN-25117 WebUI An issue where the node list is not detected when moving the agent-related widget 5.0.33
109563 GN-25081 WebUI An issue where device change approval is not processed in the IP application REST API 5.0.7, 4.0.110