Google discovered that the FireEye security equipment may be at risk
Two security researchers working for Google have discovered a simple method that puts the security of FireEye products at risk, which, oddly enough, have been installed to protect computers from attacks.
According to Google's findings, attackers can create malicious files or trick users into accessing malicious links and exploit an issue in the software of various FireEye network security products.
Using these flaws, attackers can execute code on the FireEye device as users, but can also gain administrative rights to the device if needed.
The vulnerable devices are the FireEye NX, FX, AX and EX series of network security appliances. Patches to mitigate these issues have been released by FireEye, which has also committed to providing assistance to businesses whose support contracts have expired. All of the appliances listed above have highly specialized hardware that will do only one thing: scan internet traffic for malware and other types of attacks. This type of equipment is typically installed in large corporate networks between the corporate Intranet and the outgoing/incoming Internet connecting router.
Attackers can gain access without being detected
They connect via a special monitoring point and monitor internet traffic on specific ports such as HTTP, FTP, SMTP, and so on. Whenever a file transfer is detected, the FireEye device monitors the file and scans for malicious software. Attackers exploit this behavior by sending malicious JAR files either as an email attachment or as a file on a malicious website.
The vulnerability is extremely dangerous for two main reasons. First, the device has access to all of a company's sensitive files, and second, the device also has a secondary Internet, through which it receives firmware updates, but which can be used by attackers to steal information from compromised networks.
The two researchers who discovered these issues are Tavis Ormandy and Natalie Silvanovich, members of Google’s Project Zero, an initiative established for research, disclosure and the determination of zero-day bugs in modern software and hardware products. Strangely this vulnerability belongs to Project Zero’s 666 security flaw.

