peter bassill · operator
$ cve CVE-2014-7169 JSON

CVE-2014-7169 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 99.9% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-07-28.

Description

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.94% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-07-28
Public exploityes
Published2014-09-25
Last modified2026-06-17

CISA KEV

NameGNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Added2022-01-28
Due2022-07-28
Vendor / productGNU / Bourne-Again Shell (Bash)
Ransomware usenone reported

Affected (40)

VendorProduct
aristaeos
debiandebian linux
gnubash
ibminfosphere guardium database activity monitoring
ibmpureapplication system
ibmqradar risk manager
ibmqradar security information and event manager
ibmqradar vulnerability manager
ibmsecurity access manager for mobile 8.0 firmware
ibmsecurity access manager for web 7.0 firmware
ibmsecurity access manager for web 8.0 firmware
ibmsmartcloud entry appliance
ibmsmartcloud provisioning
ibmsoftware defined network for virtual environments
ibmstarter kit for cloud
ibmstorwize v7000
ibmstorwize v7000 firmware
ibmworkload deployer
mageiamageia
opensuseopensuse
oraclelinux
qnapqts
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux for ibm z systems
redhatenterprise linux for power big endian
redhatenterprise linux for power big endian eus
redhatenterprise linux for scientific computing
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server from rhui
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatgluster storage server for on-premise
redhatvirtualization
suselinux enterprise desktop
suselinux enterprise server
suselinux enterprise software development kit
susestudio onsite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD