FireEye CM Series: CM4500, CM7500, CM9400, CM9500
FireEye CM Series: CM4500, CM7500, CM9400, CM9500, from FireEye, Inc., holds FIPS 140-2 certificate #4057 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Section 3 of the Security Policy
Certificate
| Certificate number | 4057 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | FireEye, Inc. · website |
| Hardware versions | CM4500, CM7500, CM9400, CM9500 |
| Firmware versions | 9.0.3 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The FireEye CM series is a group of management platforms that consolidates the administration, reporting, and data sharing of the FireEye NX, EX, FX and AX series in one easy-to-deploy, network-based platform. Within the FireEye deployment, the FireEye CM enables real-time sharing of the auto-generated threat intelligence to identify and block advanced attacks targeting the organization. It also enables centralized configuration, management, and reporting of FireEye platforms.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms (12)
| Algorithm | CAVP certificates |
|---|---|
| AES | C1720 |
| CKG | vendor affirmed |
| CVL | C1720 |
| DRBG | C1720, C1934 |
| DSA | C1720 |
| ECDSA | C1720 |
| HMAC | C1720, C1934 |
| KAS-SSC | vendor affirmed |
| KTS | |
| RSA | C1720 |
| SHS | C1720, C1934 |
| Triple-DES | C1720 |
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-10-28 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2021-10-28