September 8, 2015

Threat Advisory | FireEye HX 2.1 Vulnerability Update

FireEye has confirmed a vulnerability affecting its HX product version 2.1 (a legacy version, but still in use by some customers). The current release of FireEye’s HX product offering is version 2.6. FireEye has acknowledged that this vulnerability cannot be executed remotely, nor can it be exploited by an unauthenticated user.

It is recommended that customers utilizing the HX product version 2.1 update to the most recent version of the code (2.6) wherever possible. If the upgrade is not possible a dialogue with Herjavec Group and FireEye will be required so we can ensure that the issue is remediated once a patch becomes available.

