peter bassill · operator
$ cve CVE-2014-6271 JSON

CVE-2014-6271 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-07-28.

Description

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-07-28
Public exploityes
Published2014-09-24
Last modified2026-06-17

CISA KEV

NameGNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Added2022-01-28
Due2022-07-28
Vendor / productGNU / Bourne-Again Shell (Bash)
Ransomware usenone reported

Affected (40)

VendorProduct
aristaeos
debiandebian linux
gnubash
ibminfosphere guardium database activity monitoring
ibmpureapplication system
ibmqradar risk manager
ibmqradar security information and event manager
ibmqradar vulnerability manager
ibmsecurity access manager for mobile 8.0 firmware
ibmsecurity access manager for web 7.0 firmware
ibmsecurity access manager for web 8.0 firmware
ibmsmartcloud entry appliance
ibmsmartcloud provisioning
ibmsoftware defined network for virtual environments
ibmstarter kit for cloud
ibmstorwize v7000
ibmstorwize v7000 firmware
ibmworkload deployer
mageiamageia
opensuseopensuse
oraclelinux
qnapqts
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for power big endian
redhatenterprise linux for power big endian eus
redhatenterprise linux for scientific computing
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server from rhui
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatgluster storage server for on-premise
redhatvirtualization
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit
susestudio onsite

Public exploits

SourceTitleDate
exploit-dbQmail SMTP - Bash Environment Variable Injection (Metasploit)2017-10-02
exploit-dbRedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection2016-12-18
exploit-dbTrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection2016-10-21
exploit-dbIPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)2016-06-10
exploit-dbAdvantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)2015-12-02
exploit-dbCisco Unified Communications Manager - Multiple Vulnerabilities2015-08-18
exploit-dbKemp Load Master 7.1.16 - Multiple Vulnerabilities2015-04-02
exploit-dbQNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)2015-03-26
exploit-dbQNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)2015-03-26
exploit-dbPHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection2014-11-03
exploit-dbCUPS Filter - Bash Environment Variable Code Injection (Metasploit)2014-10-29
exploit-dbApache mod_cgi - 'Shellshock' Remote Command Injection2014-10-06
exploit-dbPostfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection2014-10-06
exploit-dbBash CGI - 'Shellshock' Remote Command Injection (Metasploit)2014-10-06
exploit-dbOpenVPN 2.2.29 - 'Shellshock' Remote Command Injection2014-10-04
exploit-dbPure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)2014-10-02
exploit-dbGNU bash 4.3.11 - Environment Variable dhclient2014-10-02
exploit-dbIPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection2014-10-01
exploit-dbGNU Bash - 'Shellshock' Environment Variable Command Injection2014-09-25
exploit-dbGNU Bash - Environment Variable Command Injection (Metasploit)2014-09-25
exploit-dbBash - 'Shellshock' Environment Variables Command Injection2014-09-25

References

→ the Explorer  ·  watch your stack  ·  NVD