CVE-2014-7169
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
9.8
CVSS 3.1
99.9 %
EPSS (current)
2022-01-28
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: GNU / Bourne-Again Shell (Bash)
Published: 2014-09-25 · Due (CISA): 2022-07-28
CWE: CWE-78 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| exploitdb | 34777 | GNU Bash - Environment Variable Command Injection (Metasploit) | 2014-09-25 |
| exploitdb | 34766 | Bash - 'Shellshock' Environment Variables Command Injection | 2014-09-25 |
| exploitdb | 34765 | GNU Bash - 'Shellshock' Environment Variable Command Injection | 2014-09-25 |
| exploitdb | 36933 | dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock) | 2014-09-29 |
| exploitdb | 34839 | IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection | 2014-10-01 |
| exploitdb | 34860 | GNU bash 4.3.11 - Environment Variable dhclient | 2014-10-02 |
| exploitdb | 34862 | Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit) | 2014-10-02 |
| exploitdb | 34879 | OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection | 2014-10-04 |
| exploitdb | 34895 | Bash CGI - 'Shellshock' Remote Command Injection (Metasploit) | 2014-10-06 |
| exploitdb | 34896 | Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection | 2014-10-06 |
| exploitdb | 35115 | CUPS Filter - Bash Environment Variable Code Injection (Metasploit) | 2014-10-29 |
| exploitdb | 35146 | PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection | 2014-11-03 |
| exploitdb | 36503 | QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit) | 2015-03-26 |
| exploitdb | 36504 | QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit) | 2015-03-26 |
| exploitdb | 36609 | Kemp Load Master 7.1.16 - Multiple Vulnerabilities | 2015-04-02 |
References only — no downloads or instructions.