CVE-2014-6271: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-01-28. EPSS: 100% chance of exploitation in the next 30 days.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Affected products
- Apple Mac OS X: from 10.0.0, before 10.10.0 (fixed in 10.10.0)
- Arista Eos: from 4.9.0, before 4.9.12 (fixed in 4.9.12); from 4.10.0, before 4.10.9 (fixed in 4.10.9); from 4.11.0, before 4.11.11 (fixed in 4.11.11); from 4.12.0, before 4.12.9 (fixed in 4.12.9); from 4.13.0, before 4.13.9 (fixed in 4.13.9); from 4.14.0, before 4.14.4f (fixed in 4.14.4f)
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only
- Check Point Security Gateway: before r77.30 (fixed in r77.30)
- Citrix NetScaler Sdx Firmware: before 9.3.67.5r1 (fixed in 9.3.67.5r1); from 10, before 10.1.129.11r1 (fixed in 10.1.129.11r1); from 10.5, before 10.5.52.11r1 (fixed in 10.5.52.11r1)
- Debian Debian Linux: version 7.0 only
- F5 Arx Firmware: from 6.0.0, up to and including 6.4.0
- F5 BIG-IP Access Policy Manager: from 10.1.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Advanced Firewall Manager: from 11.3.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Analytics: from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Application Acceleration Manager: from 11.4.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Application Security Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Edge Gateway: from 10.1.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
- F5 BIG-IP Global Traffic Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Link Controller: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Local Traffic Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Policy Enforcement Manager: from 11.3.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Protocol Security Module: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.4.1
- F5 BIG-IP WAN Optimization Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
- F5 BIG-IP Webaccelerator: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
- F5 BIG-IQ Cloud: from 4.0.0, up to and including 4.4.0
- F5 BIG-IQ Device: from 4.2.0, up to and including 4.4.0
- F5 BIG-IQ Security: from 4.0.0, up to and including 4.4.0
- F5 Enterprise Manager: from 2.1.0, up to and including 2.3.0; from 3.0.0, up to and including 3.1.1
- F5 Traffix Signaling Delivery Controller: from 4.0.0, up to and including 4.0.5; version 3.3.2 only; version 3.4.1 only; version 3.5.1 only; version 4.1.0 only
- and 49 more
Published 2014-09-24. Last modified 2026-06-17.