CVE-2014-7169

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

9.8
CVSS 3.1
99.9 %
EPSS (current)
2022-01-28
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: GNU / Bourne-Again Shell (Bash)

Published: 2014-09-25 · Due (CISA): 2022-07-28

CWE: CWE-78 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
exploitdb34777GNU Bash - Environment Variable Command Injection (Metasploit)2014-09-25
exploitdb34766Bash - 'Shellshock' Environment Variables Command Injection2014-09-25
exploitdb34765GNU Bash - 'Shellshock' Environment Variable Command Injection2014-09-25
exploitdb36933dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)2014-09-29
exploitdb34839IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection2014-10-01
exploitdb34860GNU bash 4.3.11 - Environment Variable dhclient2014-10-02
exploitdb34862Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)2014-10-02
exploitdb34879OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection2014-10-04
exploitdb34895Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)2014-10-06
exploitdb34896Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection2014-10-06
exploitdb35115CUPS Filter - Bash Environment Variable Code Injection (Metasploit)2014-10-29
exploitdb35146PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection2014-11-03
exploitdb36503QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)2015-03-26
exploitdb36504QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)2015-03-26
exploitdb36609Kemp Load Master 7.1.16 - Multiple Vulnerabilities2015-04-02

References only — no downloads or instructions.

Sources