CVE-2014-6271

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

9.8
CVSS 3.1
100.0 %
EPSS (current)
2022-01-28
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: GNU / Bourne-Again Shell (Bash)

Published: 2014-09-24 · Due (CISA): 2022-07-28

CWE: CWE-78 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2014/CVE-2014-6271.yamlShellShock - Remote Code Execution–
metasploitauxiliary/scanner/http/apache_mod_cgi_bash_envauxiliary/scanner/http/apache_mod_cgi_bash_env2014-09-24
metasploitauxiliary/server/dhclient_bash_envauxiliary/server/dhclient_bash_env2014-09-24
metasploitexploit/multi/ftp/pureftpd_bash_env_execexploit/multi/ftp/pureftpd_bash_env_exec2014-09-24
metasploitexploit/multi/http/apache_mod_cgi_bash_env_execexploit/multi/http/apache_mod_cgi_bash_env_exec2014-09-24
metasploitexploit/multi/http/cups_bash_env_execexploit/multi/http/cups_bash_env_exec2014-09-24
metasploitexploit/osx/local/vmware_bash_function_rootexploit/osx/local/vmware_bash_function_root2014-09-24
metasploitexploit/unix/dhcp/bash_environmentexploit/unix/dhcp/bash_environment2014-09-24
metasploitexploit/unix/smtp/qmail_bash_env_execexploit/unix/smtp/qmail_bash_env_exec2014-09-24
exploitdb34777GNU Bash - Environment Variable Command Injection (Metasploit)2014-09-25
exploitdb34766Bash - 'Shellshock' Environment Variables Command Injection2014-09-25
exploitdb34765GNU Bash - 'Shellshock' Environment Variable Command Injection2014-09-25
metasploitexploit/linux/http/ipfire_bashbug_execexploit/linux/http/ipfire_bashbug_exec2014-09-29
exploitdb34839IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection2014-10-01
exploitdb34860GNU bash 4.3.11 - Environment Variable dhclient2014-10-02
exploitdb34862Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)2014-10-02
exploitdb34879OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection2014-10-04
exploitdb34895Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)2014-10-06
exploitdb34900Apache mod_cgi - 'Shellshock' Remote Command Injection2014-10-06
exploitdb34896Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection2014-10-06
exploitdb35115CUPS Filter - Bash Environment Variable Code Injection (Metasploit)2014-10-29
exploitdb35146PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection2014-11-03
exploitdb36503QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)2015-03-26
exploitdb36504QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)2015-03-26
exploitdb36609Kemp Load Master 7.1.16 - Multiple Vulnerabilities2015-04-02
exploitdb37816Cisco Unified Communications Manager - Multiple Vulnerabilities2015-08-18
metasploitexploit/linux/http/advantech_switch_bash_env_execexploit/linux/http/advantech_switch_bash_env_exec2015-12-01
exploitdb38849Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)2015-12-02
exploitdb39918IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)2016-06-10
exploitdb40619TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection2016-10-21
exploitdb40938RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection2016-12-18
exploitdb42938Qmail SMTP - Bash Environment Variable Injection (Metasploit)2017-10-02

References only — no downloads or instructions.

Sources