Bug Fixes:
- Addresses the following security vulnerability issues published on CVE web site https://cve.mitre.org/:
- CVE-2011-3389,
- CVE-2009-3555,
- CVE-2013-2566,
- CVE-2015-2808
-
Note: For CVE-2011-3389 case, we need to disable TLSv1 protocol (under Security > Access > HTTPS> HTTPS Configuration). Since GS108Tv2 and GS110TP support only SSLv3 and TLSv1, any legacy client supporting only TLSv1 may not establish the SSL connection with the switch. So, the best way is to disable the TLSv1 mode and when required for legacy clients the mode can be enabled again. However, enabling the mode will be prone to CVE-2011-3389.
- Fixes the issue with MacBook using Thunderbolt Ethernet adapter to connect to GS108Tv2. If the Auto Power Down and Short Cable Mode are enabled on GS108Tv2 (System > Management > System Information > Green Ethernet > Green Ethernet Interface Configuration), the link will go down whenever MacBook wakes up from sleep mode.
- Fixes the issue where CFM (IEEE 802.1ag) packet is not being forwarded.
- Fixes the issue where switch always sends the same accounting session ID causing RADIUS accounting to stop working.
Known issues:
- Port PVID (Switching > VLAN > Advanced > Port PVID Configuration) does not automatically changed back to 1 after its associated VLAN is deleted.
Workaround: Manually change the PVID back to 1.
Limitations:
- Combined MAC and IP ACL do not work with double VLAN tagged traffic.
Upgrade Instructions:
This product includes software code developed by third parties, including software code subject to the GNU General Public License ("GPL") or GNU Lesser General Public License ("LGPL"). As applicable, the terms of the GPL and LGPL, and information on obtaining access to the GPL Code and LGPL Code used in this product, are available to you at . The GPL Code and LGPL Code used in this product is distributed WITHOUT ANY WARRANTY and is subject to the copyrights of one or more authors. For details, see the GPL Code and LGPL Code for this product and the terms of the GPL and LGPL.