HomeSecurityResearcher reveals 0day flaws in FireEye & puts them up for sale

Researcher reveals 0day flaws in FireEye & puts them up for sale

Researcher reveals 0day flaw in FireEye and offers others for sale

Expert Kristian Erik Hermansen has uncovered a zero-day flaw in the kernel of the Fire Eye device that could be exploited to gain remote access to the root file system.

Hermansen told CSOonline that he was working with his colleague Ron Perris when they discovered thirty vulnerabilities in a Fire Eye product, including multiple remote root issues

The expert also published a proof of concept to show how the vulnerability can be used to copy an /etc/passwd file.

This is where the bad news for FireEye begins as Hermansen claims to have discovered three more zero-days and is offering for sale. Hermansen claims to have found a login bypass vulnerability, and command injection vulnerabilities.

FireEye-Zero-day-726x400

The flaw appears to affect a PHP script on the Fire Eye device, the expert publicly criticized the popular security services company.

Hermansen published the PoC for the Fire Eye remote root file system access 0-day on Pastebin, offering all the vulnerabilities for sale and the base asking for a reward of an amount starting at around $10,000 per bug.

Hermansen made headlines after revealing a series of security issues on the Covered California website, as reported in Forbes:

“Hermansen discovered a vulnerability that would allow someone to take control of another person’s account on the California site, and review or change the information registered there. He tried to contact Covered California “at least 15 times” via email, phone or chat about the problem, but got no response for over a month. “They must have been inundated with people looking for help with the site,” he said. “

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS