← Back to CVE List
Vulnerability Intelligence Report
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

CVE-2014-6271

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
gnu bash all
arista eos all
oracle linux 4, 5, 6
qnap qts 4.1.1
mageia mageia 3.0, 4.0
redhat gluster_storage_server_for_on-premise 2.1
redhat virtualization 3.4
redhat enterprise_linux 4.0, 5.0, 6.0, 7.0
redhat enterprise_linux_desktop 5.0, 6.0, 7.0
redhat enterprise_linux_eus 5.9, 6.4, 6.5, 7.3, 7.4, 7.5, 7.6, 7.7
redhat enterprise_linux_for_ibm_z_systems 5.9_s390x, 6.4_s390x, 6.5_s390x, 7.3_s390x, 7.4_s390x, 7.5_s390x, 7.6_s390x, 7.7_s390x
redhat enterprise_linux_for_power_big_endian 5.0_ppc, 5.9_ppc, 6.0_ppc64, 6.4_ppc64, 7.0_ppc64
redhat enterprise_linux_for_power_big_endian_eus 6.5_ppc64, 7.3_ppc64, 7.4_ppc64, 7.5_ppc64, 7.6_ppc64, 7.7_ppc64
redhat enterprise_linux_for_scientific_computing 6.0, 7.0
redhat enterprise_linux_server 5.0, 6.0, 7.0
redhat enterprise_linux_server_aus 5.6, 5.9, 6.2, 6.4, 6.5, 7.3, 7.4, 7.6, 7.7
redhat enterprise_linux_server_from_rhui 5.0, 6.0, 7.0
redhat enterprise_linux_server_tus 6.5, 7.3, 7.6, 7.7
redhat enterprise_linux_workstation 5.0, 6.0, 7.0
suse studio_onsite 1.3
opensuse opensuse 12.3, 13.1, 13.2
suse linux_enterprise_desktop 11, 12
suse linux_enterprise_server 10, 11, 12
suse linux_enterprise_software_development_kit 11, 12
debian debian_linux 7.0
ibm infosphere_guardium_database_activity_monitoring 8.2, 9.0, 9.1
ibm pureapplication_system 2.0.0.0
ibm qradar_risk_manager 7.1.0
ibm qradar_security_information_and_event_manager 7.1.0, 7.1.1, 7.1.2, 7.2, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.8.15, 7.2.9
ibm qradar_vulnerability_manager 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.6, 7.2.8
ibm smartcloud_entry_appliance 2.3.0, 2.4.0, 3.1.0, 3.2.0
ibm smartcloud_provisioning 2.1.0
ibm software_defined_network_for_virtual_environments all
ibm starter_kit_for_cloud 2.2.0
ibm workload_deployer all
ibm security_access_manager_for_mobile_8.0_firmware 8.0.0.1, 8.0.0.2, 8.0.0.3, 8.0.0.5
ibm security_access_manager_for_web_7.0_firmware 7.0.0.1, 7.0.0.2, 7.0.0.3, 7.0.0.4, 7.0.0.5, 7.0.0.6, 7.0.0.7, 7.0.0.8
ibm security_access_manager_for_web_8.0_firmware 8.0.0.2, 8.0.0.3, 8.0.0.5
ibm storwize_v7000_firmware all
ibm storwize_v7000 all
ibm storwize_v5000_firmware all
ibm storwize_v5000 all
ibm storwize_v3700_firmware all
ibm storwize_v3700 all
ibm storwize_v3500_firmware all
ibm storwize_v3500 all
ibm flex_system_v7000_firmware all
ibm flex_system_v7000 all
ibm san_volume_controller_firmware all
ibm san_volume_controller all
ibm stn6500_firmware all
ibm stn6500 all
ibm stn6800_firmware all
ibm stn6800 all
ibm stn7800_firmware all
ibm stn7800 all
canonical ubuntu_linux 10.04, 12.04, 14.04
novell zenworks_configuration_management 10.3, 11, 11.1, 11.2, 11.3.0
novell open_enterprise_server 2.0, 11.0
checkpoint security_gateway all
f5 big-ip_access_policy_manager 11.6.0
f5 big-ip_advanced_firewall_manager 11.6.0
f5 big-ip_analytics 11.6.0
f5 big-ip_application_acceleration_manager 11.6.0
f5 big-ip_application_security_manager 11.6.0
f5 big-ip_edge_gateway all
f5 big-ip_global_traffic_manager 11.6.0
f5 big-ip_link_controller 11.6.0
f5 big-ip_local_traffic_manager 11.6.0
f5 big-ip_policy_enforcement_manager 11.6.0
f5 big-ip_protocol_security_module all
f5 big-ip_wan_optimization_manager all
f5 big-ip_webaccelerator all
f5 big-iq_cloud all
f5 big-iq_device all
f5 big-iq_security all
f5 enterprise_manager all
f5 traffix_signaling_delivery_controller 3.3.2, 3.4.1, 3.5.1, 4.1.0
f5 arx_firmware all
f5 arx all
citrix netscaler_sdx_firmware all
citrix netscaler_sdx all
apple mac_os_x all
vmware vcenter_server_appliance 5.0, 5.1, 5.5
vmware esx 4.0, 4.1

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.999%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDebian GNU/Linux · Vendor · USA
Reserved2014-09-09T00:00:00
Published2014-09-24T18:00:00
Patch Date2014-09-24
Last Updated2025-10-22T00:05:36

LINK COPIED TO CLIPBOARD