CVE-2014-7169 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-07-28.
Description
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.94% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2022-07-28 |
| Public exploit | yes |
| Published | 2014-09-25 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability |
|---|---|
| Added | 2022-01-28 |
| Due | 2022-07-28 |
| Vendor / product | GNU / Bourne-Again Shell (Bash) |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| arista | eos |
| debian | debian linux |
| gnu | bash |
| ibm | infosphere guardium database activity monitoring |
| ibm | pureapplication system |
| ibm | qradar risk manager |
| ibm | qradar security information and event manager |
| ibm | qradar vulnerability manager |
| ibm | security access manager for mobile 8.0 firmware |
| ibm | security access manager for web 7.0 firmware |
| ibm | security access manager for web 8.0 firmware |
| ibm | smartcloud entry appliance |
| ibm | smartcloud provisioning |
| ibm | software defined network for virtual environments |
| ibm | starter kit for cloud |
| ibm | storwize v7000 |
| ibm | storwize v7000 firmware |
| ibm | workload deployer |
| mageia | mageia |
| opensuse | opensuse |
| oracle | linux |
| qnap | qts |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for power big endian |
| redhat | enterprise linux for power big endian eus |
| redhat | enterprise linux for scientific computing |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server from rhui |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| redhat | gluster storage server for on-premise |
| redhat | virtualization |
| suse | linux enterprise desktop |
| suse | linux enterprise server |
| suse | linux enterprise software development kit |
| suse | studio onsite |
Public exploits
References
- http://advisories.mageia.org/MGASA-2014-0393.html
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html
- http://jvn.jp/en/jp/JVN55667175/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126
- http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html
- http://linux.oracle.com/errata/ELSA-2014-1306.html
- http://linux.oracle.com/errata/ELSA-2014-3075.html
- http://linux.oracle.com/errata/ELSA-2014-3077.html
- http://linux.oracle.com/errata/ELSA-2014-3078.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00042.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00048.html
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html
- http://marc.info/?l=bugtraq&m=141216207813411&w=2
- http://marc.info/?l=bugtraq&m=141216668515282&w=2
- http://marc.info/?l=bugtraq&m=141235957116749&w=2
→ the Explorer · watch your stack · NVD