CVE Feed

    Dashboard / CVE / CVE-2014-6271

    CVE-2014-6271

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

    Published:Sep 24, 2014
    Last Modified:Apr 22, 2026
    EPS:Sep 24, 2014
    EPSS Score:0.9422
    CVSS Score:9.8

    CISA Notification

    Description

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Jul 28, 2022
    1506 days ago
    Alert Date
    Jan 28, 2022
    1687 days ago

    Affected Products

    Vendor
    Apple
    Product
    Mac Os X
    Vendor
    Arista
    Product
    Eos
    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Checkpoint
    Product
    Security Gateway
    Vendor
    Citrix
    Product
    Netscaler Sdx
    Vendor
    Citrix
    Product
    Netscaler Sdx Firmware
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    F5
    Product
    Arx
    Vendor
    F5
    Product
    Arx Firmware
    Vendor
    F5
    Product
    Big-ip Access Policy Manager
    Vendor
    F5
    Product
    Big-ip Advanced Firewall Manager
    Vendor
    F5
    Product
    Big-ip Analytics
    Vendor
    F5
    Product
    Big-ip Application Acceleration Manager
    Vendor
    F5
    Product
    Big-ip Application Security Manager
    Vendor
    F5
    Product
    Big-ip Edge Gateway
    Vendor
    F5
    Product
    Big-ip Global Traffic Manager
    Vendor
    F5
    Product
    Big-ip Link Controller
    Vendor
    F5
    Product
    Big-ip Local Traffic Manager
    Vendor
    F5
    Product
    Big-ip Policy Enforcement Manager
    Vendor
    F5
    Product
    Big-ip Protocol Security Module
    Vendor
    F5
    Product
    Big-ip Wan Optimization Manager
    Vendor
    F5
    Product
    Big-ip Webaccelerator
    Vendor
    F5
    Product
    Big-iq Cloud
    Vendor
    F5
    Product
    Big-iq Device
    Vendor
    F5
    Product
    Big-iq Security
    Vendor
    F5
    Product
    Enterprise Manager
    Vendor
    F5
    Product
    Traffix Signaling Delivery Controller
    Vendor
    Gnu
    Product
    Bash
    Vendor
    Ibm
    Product
    Flex System V7000
    Vendor
    Ibm
    Product
    Flex System V7000 Firmware
    Vendor
    Ibm
    Product
    Infosphere Guardium Database Activity Monitoring
    Vendor
    Ibm
    Product
    Pureapplication System
    Vendor
    Ibm
    Product
    Qradar Risk Manager
    Vendor
    Ibm
    Product
    Qradar Security Information And Event Manager
    Vendor
    Ibm
    Product
    Qradar Vulnerability Manager
    Vendor
    Ibm
    Product
    San Volume Controller
    Vendor
    Ibm
    Product
    San Volume Controller Firmware
    Vendor
    Ibm
    Product
    Security Access Manager For Mobile 8.0 Firmware
    Vendor
    Ibm
    Product
    Security Access Manager For Web 7.0 Firmware
    Vendor
    Ibm
    Product
    Security Access Manager For Web 8.0 Firmware
    Vendor
    Ibm
    Product
    Smartcloud Entry Appliance
    Vendor
    Ibm
    Product
    Smartcloud Provisioning
    Vendor
    Ibm
    Product
    Software Defined Network For Virtual Environments
    Vendor
    Ibm
    Product
    Starter Kit For Cloud
    Vendor
    Ibm
    Product
    Stn6500
    Vendor
    Ibm
    Product
    Stn6500 Firmware
    Vendor
    Ibm
    Product
    Stn6800
    Vendor
    Ibm
    Product
    Stn6800 Firmware
    Vendor
    Ibm
    Product
    Stn7800
    Vendor
    Ibm
    Product
    Stn7800 Firmware
    Vendor
    Ibm
    Product
    Storwize V3500
    Vendor
    Ibm
    Product
    Storwize V3500 Firmware
    Vendor
    Ibm
    Product
    Storwize V3700
    Vendor
    Ibm
    Product
    Storwize V3700 Firmware
    Vendor
    Ibm
    Product
    Storwize V5000
    Vendor
    Ibm
    Product
    Storwize V5000 Firmware
    Vendor
    Ibm
    Product
    Storwize V7000
    Vendor
    Ibm
    Product
    Storwize V7000 Firmware
    Vendor
    Ibm
    Product
    Workload Deployer
    Vendor
    Mageia
    Product
    Mageia
    Vendor
    Novell
    Product
    Open Enterprise Server
    Vendor
    Novell
    Product
    Zenworks Configuration Management
    Vendor
    Opensuse
    Product
    Opensuse
    Vendor
    Oracle
    Product
    Linux
    Vendor
    Qnap
    Product
    Qts
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Enterprise Linux Desktop
    Vendor
    Redhat
    Product
    Enterprise Linux Eus
    Vendor
    Redhat
    Product
    Enterprise Linux For Ibm Z Systems
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Big Endian
    Vendor
    Redhat
    Product
    Enterprise Linux For Power Big Endian Eus
    Vendor
    Redhat
    Product
    Enterprise Linux For Scientific Computing
    Vendor
    Redhat
    Product
    Enterprise Linux Server
    Vendor
    Redhat
    Product
    Enterprise Linux Server Aus
    Vendor
    Redhat
    Product
    Enterprise Linux Server From Rhui
    Vendor
    Redhat
    Product
    Enterprise Linux Server Tus
    Vendor
    Redhat
    Product
    Enterprise Linux Workstation
    Vendor
    Redhat
    Product
    Gluster Storage Server For On-premise
    Vendor
    Redhat
    Product
    Rhel Els
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Redhat
    Product
    Rhel Mission Critical
    Vendor
    Redhat
    Product
    Rhel Sjis
    Vendor
    Redhat
    Product
    Rhev Manager
    Vendor
    Redhat
    Product
    Virtualization
    Vendor
    Suse
    Product
    Linux Enterprise Desktop
    Vendor
    Suse
    Product
    Linux Enterprise Server
    Vendor
    Suse
    Product
    Linux Enterprise Software Development Kit
    Vendor
    Suse
    Product
    Studio Onsite
    Vendor
    Vmware
    Product
    Esx
    Vendor
    Vmware
    Product
    Vcenter Server Appliance

    Exploits

    http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.htmlhttp://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.htmlhttp://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.htmlhttp://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.htmlhttps://access.redhat.com/articles/1200223https://access.redhat.com/node/1200223https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/https://www.exploit-db.com/exploits/34879/https://www.exploit-db.com/exploits/37816/https://www.exploit-db.com/exploits/38849/https://www.exploit-db.com/exploits/39918/https://www.exploit-db.com/exploits/40619/https://www.exploit-db.com/exploits/40938/https://www.exploit-db.com/exploits/42938/http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.htmlhttp://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.htmlhttp://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.htmlhttp://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.htmlhttps://access.redhat.com/articles/1200223https://access.redhat.com/node/1200223https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/https://www.exploit-db.com/exploits/34879/https://www.exploit-db.com/exploits/37816/https://www.exploit-db.com/exploits/38849/https://www.exploit-db.com/exploits/39918/https://www.exploit-db.com/exploits/40619/https://www.exploit-db.com/exploits/40938/https://www.exploit-db.com/exploits/42938/https://www.exploit-db.com/exploits/38849https://github.com/0x00-0x00/CVE-2014-6271https://github.com/0xAshwesker/CVE-2014-6271https://github.com/0xBlackash/CVE-2014-6271https://github.com/0xN7y/CVE-2014-6271https://github.com/352926/shellshock_crawlerhttps://github.com/ajansha/shellshockhttps://github.com/akiraaisha/shellshocker-pythonhttps://github.com/akr3ch/CVE-2014-6271https://github.com/AlissonFaoli/Shellshockhttps://github.com/ambjlou/it355-lab4-enterprise-lan-securityhttps://github.com/andres101c/Shellshock-CVE-2014-6271https://github.com/Anklebiter87/Cgi-bin_bash_Reversehttps://github.com/anujbhan/shellshock-victim-hosthttps://github.com/Any3ite/CVE-2014-6271https://github.com/APSL/salt-shellshockhttps://github.com/ariarijp/vagrant-shellshockhttps://github.com/Aruthw/CVE-2014-6271https://github.com/b4keSn4ke/CVE-2014-6271https://github.com/Brandaoo/CVE-2014-6271https://github.com/caverm/Shellshock_CVE-2014-6271https://github.com/cj1324/CGIShellhttps://github.com/cved-sources/cve-2014-6271https://github.com/cyberexpert111/Blind-SSRF-to-Remote-Code-Execution-Shellshock-Professional-Bug-Bounty-Reporthttps://github.com/cyberharsh/Shellbash-CVE-2014-6271https://github.com/Dilith006/CVE-2014-6271https://github.com/dlitz/bash-cve-2014-6271-fixeshttps://github.com/DrHaitham/CVE-2014-6271-Shellshock-https://github.com/FacundoMfernandez/pentesting-obiobahttps://github.com/FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-https://github.com/francisck/shellshock-cgihttps://github.com/FREEGUY-6/dmz-security-monitoring-hardeninghttps://github.com/gabemarshall/shocknawwhttps://github.com/Gurguii/cgi-bin-shellshockhttps://github.com/hackintoanetwork/shellshockhttps://github.com/hadrian3689/shellshockhttps://github.com/hanmin0512/CVE-2014-6271_pwnablehttps://github.com/heikipikker/shellshock-shellhttps://github.com/HevenTafese/Penetration-Testing-Walkthrough-Hacksudo-Thorhttps://github.com/hmlio/vaas-cve-2014-6271https://github.com/huanlu/cve-2014-6271-huan-luhttps://github.com/ilismal/Nessus_CVE-2014-6271_checkhttps://github.com/im2sinister/CVE-2014-6271https://github.com/indiandragon/Shellshock-Vulnerability-Scanhttps://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-Shellshockhttps://github.com/internero/debian-lenny-bash_3.2.52-cve-2014-6271https://github.com/J0hnTh3Kn1ght/CVE-2014-6271https://github.com/jblaine/cookbook-bash-CVE-2014-6271https://github.com/Jsmoreira02/CVE-2014-6271https://github.com/justzx2011/bash-uphttps://github.com/K3ysTr0K3R/CVE-2014-6271-EXPLOIThttps://github.com/kaleth4/CVE-2014-6271https://github.com/kaleth4/-CVE-2014-6271https://github.com/kelleykong/cve-2014-6271-mengjia-konghttps://github.com/knightc0de/Shellshock_vuln_Exploithttps://github.com/kowshik-sundararajan/CVE-2014-6271https://github.com/mattclegg/CVE-2014-6271https://github.com/mochizuki875/CVE-2014-6271-Apache-Debianhttps://github.com/moften/CVE-2014-6271https://github.com/mritunjay-k/CVE-2014-6271https://github.com/mtaha-sec/bash-apocalypsehttps://github.com/MuirlandOracle/CVE-2014-6271-IPFirehttps://github.com/npm/ansible-bashpocalypsehttps://github.com/opsxcq/exploit-CVE-2014-6271https://github.com/P0cL4bs/ShellShock-CGI-Scanhttps://github.com/Pilou-Pilou/docker_CVE-2014-6271.https://github.com/proclnas/ShellShock-CGI-Scanhttps://github.com/R3fr4kt/Shocker-TJNULL-OSCP-https://github.com/RadYio/CVE-2014-6271https://github.com/RainMak3r/Rainstormhttps://github.com/RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysishttps://github.com/ramnes/pyshellshockhttps://github.com/rashmikadileeshara/CVE-2014-6271-Shellshock-https://github.com/renanvicente/puppet-shellshockhttps://github.com/rrreeeyyy/cve-2014-6271-spechttps://github.com/rsherstnev/CVE-2014-6271https://github.com/ryancnelson/patched-bash-4.3https://github.com/ryeyao/CVE-2014-6271_Testhttps://github.com/sch3m4/RIShttps://github.com/scottjpack/shellshock_scannerhttps://github.com/securusglobal/BadBashhttps://github.com/shawntns/exploit-CVE-2014-6271https://github.com/Sindadziy/cve-2014-6271https://github.com/Sindayifu/CVE-2019-14287-CVE-2014-6271https://github.com/somhm-solutions/Shell-Shockhttps://github.com/sunnyjiang/shellshocker-androidhttps://github.com/teedeedubya/bash-fix-exploithttps://github.com/themson/shellshockhttps://github.com/TheRealCiscoo/Shellshock-Exploithttps://github.com/TheRealCiscoo/shellshock-pochttps://github.com/u20024804/bash-3.2-fixed-CVE-2014-6271https://github.com/u20024804/bash-4.2-fixed-CVE-2014-6271https://github.com/u20024804/bash-4.3-fixed-CVE-2014-6271https://github.com/V3nG4mxV1p3r/Mobile-Drop-Device-SOC-Detectionhttps://github.com/Vaibhav91one/shellshock-cve-labhttps://github.com/villadora/CVE-2014-6271https://github.com/w4fz5uck5/ShockZaum-CVE-2014-6271https://github.com/wenyu1999/bash-shellshockhttps://github.com/woltage/CVE-2014-6271https://github.com/YunchoHang/CVE-2014-6271-SHELLSHOCKhttps://github.com/zalalov/CVE-2014-6271https://www.exploit-db.com/exploits/34765https://www.exploit-db.com/exploits/34766https://www.exploit-db.com/exploits/34777https://www.exploit-db.com/exploits/34839https://www.exploit-db.com/exploits/34860https://www.exploit-db.com/exploits/34862https://www.exploit-db.com/exploits/34879https://www.exploit-db.com/exploits/34895https://www.exploit-db.com/exploits/34896https://www.exploit-db.com/exploits/34900https://www.exploit-db.com/exploits/35115https://www.exploit-db.com/exploits/35146https://www.exploit-db.com/exploits/36503https://www.exploit-db.com/exploits/36504https://www.exploit-db.com/exploits/36609https://www.exploit-db.com/exploits/37816https://www.exploit-db.com/exploits/39918https://www.exploit-db.com/exploits/40619https://www.exploit-db.com/exploits/40938https://www.exploit-db.com/exploits/42938

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High