Vulnerability Intelligence Report
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| gnu | bash | all |
| arista | eos | all |
| oracle | linux | 4, 5, 6 |
| qnap | qts | 4.1.1 |
| mageia | mageia | 3.0, 4.0 |
| redhat | gluster_storage_server_for_on-premise | 2.1 |
| redhat | virtualization | 3.4 |
| redhat | enterprise_linux | 4.0, 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_desktop | 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_eus | 5.9, 6.4, 6.5, 7.3, 7.4, 7.5, 7.6, 7.7 |
| redhat | enterprise_linux_for_ibm_z_systems | 5.9_s390x, 6.4_s390x, 6.5_s390x, 7.3_s390x, 7.4_s390x, 7.5_s390x, 7.6_s390x, 7.7_s390x |
| redhat | enterprise_linux_for_power_big_endian | 5.0_ppc, 5.9_ppc, 6.0_ppc64, 6.4_ppc64, 7.0_ppc64 |
| redhat | enterprise_linux_for_power_big_endian_eus | 6.5_ppc64, 7.3_ppc64, 7.4_ppc64, 7.5_ppc64, 7.6_ppc64, 7.7_ppc64 |
| redhat | enterprise_linux_for_scientific_computing | 6.0, 7.0 |
| redhat | enterprise_linux_server | 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_server_aus | 5.6, 5.9, 6.2, 6.4, 6.5, 7.3, 7.4, 7.6, 7.7 |
| redhat | enterprise_linux_server_from_rhui | 5.0, 6.0, 7.0 |
| redhat | enterprise_linux_server_tus | 6.5, 7.3, 7.6, 7.7 |
| redhat | enterprise_linux_workstation | 5.0, 6.0, 7.0 |
| suse | studio_onsite | 1.3 |
| opensuse | opensuse | 12.3, 13.1, 13.2 |
| suse | linux_enterprise_desktop | 11, 12 |
| suse | linux_enterprise_server | 10, 11, 12 |
| suse | linux_enterprise_software_development_kit | 11, 12 |
| debian | debian_linux | 7.0 |
| ibm | infosphere_guardium_database_activity_monitoring | 8.2, 9.0, 9.1 |
| ibm | pureapplication_system | 2.0.0.0 |
| ibm | qradar_risk_manager | 7.1.0 |
| ibm | qradar_security_information_and_event_manager | 7.1.0, 7.1.1, 7.1.2, 7.2, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.8.15, 7.2.9 |
| ibm | qradar_vulnerability_manager | 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.6, 7.2.8 |
| ibm | smartcloud_entry_appliance | 2.3.0, 2.4.0, 3.1.0, 3.2.0 |
| ibm | smartcloud_provisioning | 2.1.0 |
| ibm | software_defined_network_for_virtual_environments | all |
| ibm | starter_kit_for_cloud | 2.2.0 |
| ibm | workload_deployer | all |
| ibm | security_access_manager_for_mobile_8.0_firmware | 8.0.0.1, 8.0.0.2, 8.0.0.3, 8.0.0.5 |
| ibm | security_access_manager_for_web_7.0_firmware | 7.0.0.1, 7.0.0.2, 7.0.0.3, 7.0.0.4, 7.0.0.5, 7.0.0.6, 7.0.0.7, 7.0.0.8 |
| ibm | security_access_manager_for_web_8.0_firmware | 8.0.0.2, 8.0.0.3, 8.0.0.5 |
| ibm | storwize_v7000_firmware | all |
| ibm | storwize_v7000 | all |
| ibm | storwize_v5000_firmware | all |
| ibm | storwize_v5000 | all |
| ibm | storwize_v3700_firmware | all |
| ibm | storwize_v3700 | all |
| ibm | storwize_v3500_firmware | all |
| ibm | storwize_v3500 | all |
| ibm | flex_system_v7000_firmware | all |
| ibm | flex_system_v7000 | all |
| ibm | san_volume_controller_firmware | all |
| ibm | san_volume_controller | all |
| ibm | stn6500_firmware | all |
| ibm | stn6500 | all |
| ibm | stn6800_firmware | all |
| ibm | stn6800 | all |
| ibm | stn7800_firmware | all |
| ibm | stn7800 | all |
| canonical | ubuntu_linux | 10.04, 12.04, 14.04 |
| novell | zenworks_configuration_management | 10.3, 11, 11.1, 11.2, 11.3.0 |
| novell | open_enterprise_server | 2.0, 11.0 |
| checkpoint | security_gateway | all |
| f5 | big-ip_access_policy_manager | 11.6.0 |
| f5 | big-ip_advanced_firewall_manager | 11.6.0 |
| f5 | big-ip_analytics | 11.6.0 |
| f5 | big-ip_application_acceleration_manager | 11.6.0 |
| f5 | big-ip_application_security_manager | 11.6.0 |
| f5 | big-ip_edge_gateway | all |
| f5 | big-ip_global_traffic_manager | 11.6.0 |
| f5 | big-ip_link_controller | 11.6.0 |
| f5 | big-ip_local_traffic_manager | 11.6.0 |
| f5 | big-ip_policy_enforcement_manager | 11.6.0 |
| f5 | big-ip_protocol_security_module | all |
| f5 | big-ip_wan_optimization_manager | all |
| f5 | big-ip_webaccelerator | all |
| f5 | big-iq_cloud | all |
| f5 | big-iq_device | all |
| f5 | big-iq_security | all |
| f5 | enterprise_manager | all |
| f5 | traffix_signaling_delivery_controller | 3.3.2, 3.4.1, 3.5.1, 4.1.0 |
| f5 | arx_firmware | all |
| f5 | arx | all |
| citrix | netscaler_sdx_firmware | all |
| citrix | netscaler_sdx | all |
| apple | mac_os_x | all |
| vmware | vcenter_server_appliance | 5.0, 5.1, 5.5 |
| vmware | esx | 4.0, 4.1 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.999%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Debian GNU/Linux · Vendor · USA |
| Reserved | 2014-09-09T00:00:00 |
| Published | 2014-09-24T18:00:00 |
| Patch Date | 2014-09-24 |
| Last Updated | 2025-10-22T00:05:36 |
Community Chatter & Buzz