CVE-2014-7169: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-01-28. EPSS: 99.9% chance of exploitation in the next 30 days.
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Affected products
- Apple Mac OS X: from 10.0.0, before 10.10.0 (fixed in 10.10.0)
- Arista Eos: from 4.9.0, before 4.9.12 (fixed in 4.9.12); from 4.10.0, before 4.10.9 (fixed in 4.10.9); from 4.11.0, before 4.11.11 (fixed in 4.11.11); from 4.12.0, before 4.12.9 (fixed in 4.12.9); from 4.13.0, before 4.13.9 (fixed in 4.13.9); from 4.14.0, before 4.14.4f (fixed in 4.14.4f)
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 14.04 only
- Check Point Security Gateway: before r77.30 (fixed in r77.30)
- Citrix NetScaler Sdx Firmware: before 9.3.67.5r1 (fixed in 9.3.67.5r1); from 10, before 10.1.129.11r1 (fixed in 10.1.129.11r1); from 10.5, before 10.5.52.11r1 (fixed in 10.5.52.11r1)
- Debian Debian Linux: version 7.0 only
- F5 Arx Firmware: from 6.0.0, up to and including 6.4.0
- F5 BIG-IP Access Policy Manager: from 10.1.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Advanced Firewall Manager: from 11.3.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Analytics: from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Application Acceleration Manager: from 11.4.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Application Security Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Edge Gateway: from 10.1.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
- F5 BIG-IP Global Traffic Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Link Controller: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Local Traffic Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Policy Enforcement Manager: from 11.3.0, up to and including 11.5.1; version 11.6.0 only
- F5 BIG-IP Protocol Security Module: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.4.1
- F5 BIG-IP WAN Optimization Manager: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
- F5 BIG-IP Webaccelerator: from 10.0.0, up to and including 10.2.4; from 11.0.0, up to and including 11.3.0
- F5 BIG-IQ Cloud: from 4.0.0, up to and including 4.4.0
- F5 BIG-IQ Device: from 4.2.0, up to and including 4.4.0
- F5 BIG-IQ Security: from 4.0.0, up to and including 4.4.0
- F5 Enterprise Manager: from 2.1.0, up to and including 2.3.0; from 3.0.0, up to and including 3.1.1
- F5 Traffix Signaling Delivery Controller: from 4.0.0, up to and including 4.0.5; version 3.3.2 only; version 3.4.1 only; version 3.5.1 only; version 4.1.0 only
- and 49 more
Published 2014-09-25. Last modified 2026-06-17.