fireeye CVE Vulnerabilities & Metrics

Focus on fireeye vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About fireeye Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with fireeye. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total fireeye CVEs: 10
Earliest CVE date: 26 Oct 2020, 19:15 UTC
Latest CVE date: 15 Jan 2024, 17:15 UTC

Latest CVE reference: CVE-2024-0320

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical fireeye CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.2

Max CVSS: 4.0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 3
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS fireeye CVEs

These are the five CVEs with the highest CVSS scores for fireeye, sorted by severity first and recency.

All CVEs for fireeye

CVE-2024-0320 fireeye vulnerability CVSS: 0 15 Jan 2024, 17:15 UTC

Cross-Site Scripting in FireEye Malware Analysis (AX) affecting version 9.0.3.936530. This vulnerability allows an attacker to send a specially crafted JavaScript payload in the application URL to retrieve the session details of a legitimate user.

CVE-2024-0319 fireeye vulnerability CVSS: 0 15 Jan 2024, 17:15 UTC

Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious page by changing the 'redirect_uri' parameter.

CVE-2024-0318 fireeye vulnerability CVSS: 0 15 Jan 2024, 17:15 UTC

Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and 'Hostname/IP' parameters that will be triggered when items are loaded.

CVE-2024-0317 fireeye vulnerability CVSS: 0 15 Jan 2024, 17:15 UTC

Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' parameters to an authenticated user to retrieve their session details.

CVE-2024-0316 fireeye vulnerability CVSS: 0 15 Jan 2024, 16:15 UTC

Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the containment_notify/preview parameter, which could lead to a service outage.

CVE-2024-0315 fireeye vulnerability CVSS: 0 15 Jan 2024, 16:15 UTC

Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system during the report creation process.

CVE-2024-0314 fireeye vulnerability CVSS: 0 15 Jan 2024, 16:15 UTC

XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking.

CVE-2021-28970 fireeye vulnerability CVSS: 4.0 01 Apr 2021, 20:15 UTC

eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.

CVE-2021-28969 fireeye vulnerability CVSS: 4.0 01 Apr 2021, 20:15 UTC

eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3. NOTE: this is different from CVE-2020-25034 and affects newer versions of the software.

CVE-2020-25034 fireeye vulnerability CVSS: 4.0 26 Oct 2020, 19:15 UTC

eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email search feature.