KEVIntel
9.8
CVSS
Critical

CVE-2014-6271

PUBLISHED

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to...

Exploited in the wild Remote Low complexity No user interaction
Vendor
GNU
Product
Bash
Published
Sep 24, 2014
EPSS

Description

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

apache cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-01-28 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

References

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 28, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

advantech_switch_bash_env_exec

metasploit · Created Unknown

Metasploit module for CVE-2014-6271

qmail_bash_env_exec

metasploit · Created Unknown

Metasploit module for CVE-2014-6271

bash_environment

metasploit · Created Unknown

Metasploit module for CVE-2014-6271

vmware_bash_function_root

metasploit · Created Unknown

Metasploit module for CVE-2014-6271

pureftpd_bash_env_exec

metasploit · Created Unknown

Metasploit module for CVE-2014-6271

ipfire_bashbug_exec

metasploit · Created Unknown

Metasploit module for CVE-2014-6271

YunchoHang/CVE-2014-6271-SHELLSHOCK

github · Created 2025-02-26 10:36:45 UTC · 0 stars

Automation script to exploit the Shellshock vulnerability.

RadYio/CVE-2014-6271

github · Created 2024-11-26 09:07:24 UTC · 0 stars

Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible

K3ysTr0K3R/CVE-2014-6271-EXPLOIT

github · Created 2024-05-18 19:42:58 UTC · 2 stars

A PoC exploit for CVE-2014-6271 - Shellshock

0xN7y/CVE-2014-6271

github · Created 2023-10-31 06:48:30 UTC · 1 stars

EXPLOIT FOR CVE-2014-6271

hanmin0512/CVE-2014-6271_pwnable

github · Created 2023-08-29 06:58:26 UTC · 0 stars

Jsmoreira02/CVE-2014-6271

github · Created 2023-07-01 03:50:02 UTC · 0 stars

Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi

Brandaoo/CVE-2014-6271

github · Created 2023-03-25 05:32:59 UTC · 0 stars

mritunjay-k/CVE-2014-6271

github · Created 2023-03-02 17:30:03 UTC · 0 stars

FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-

github · Created 2022-09-09 10:44:25 UTC · 0 stars

[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing

akr3ch/CVE-2014-6271

github · Created 2022-04-02 07:30:31 UTC · 3 stars

ShellShock interactive-shell exploit

b4keSn4ke/CVE-2014-6271

github · Created 2021-07-29 04:51:43 UTC · 14 stars

Shellshock exploit aka CVE-2014-6271

mochizuki875/CVE-2014-6271-Apache-Debian

github · Created 2021-07-24 07:47:55 UTC · 1 stars

This Repo is PoC environment of CVE-2014-6271(https://nvd.nist.gov/vuln/detail/cve-2014-6271).

MuirlandOracle/CVE-2014-6271-IPFire

github · Created 2020-11-12 04:12:55 UTC · 0 stars

cyberharsh/Shellbash-CVE-2014-6271

github · Created 2020-06-26 11:08:22 UTC · 0 stars

Dilith006/CVE-2014-6271

github · Created 2020-05-12 18:37:14 UTC · 0 stars

rashmikadileeshara/CVE-2014-6271-Shellshock-

github · Created 2020-05-12 17:51:06 UTC · 0 stars

This is an individual assignment for secure network programming

Any3ite/CVE-2014-6271

github · Created 2020-01-06 08:24:35 UTC · 1 stars

shawntns/exploit-CVE-2014-6271

github · Created 2019-04-27 18:55:39 UTC · 0 stars

Aruthw/CVE-2014-6271

github · Created 2018-06-30 13:26:20 UTC · 0 stars

w4fz5uck5/ShockZaum-CVE-2014-6271

github · Created 2018-06-18 16:09:15 UTC · 0 stars

Shellshock vulnerability attacker

kowshik-sundararajan/CVE-2014-6271

github · Created 2018-05-05 05:50:50 UTC · 0 stars

CS4238 Computer Security Practices

0x00-0x00/CVE-2014-6271

github · Created 2017-11-23 14:45:22 UTC · 3 stars

Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.

zalalov/CVE-2014-6271

github · Created 2017-04-30 19:47:00 UTC · 6 stars

Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell

Pilou-Pilou/docker_CVE-2014-6271.

github · Created 2017-01-25 21:51:52 UTC · 0 stars

opsxcq/exploit-CVE-2014-6271

github · Created 2016-12-07 23:38:50 UTC · 211 stars

Shellshock exploit + vulnerable environment

ryeyao/CVE-2014-6271_Test

github · Created 2014-09-29 13:16:08 UTC · 1 stars

u20024804/bash-4.3-fixed-CVE-2014-6271

github · Created 2014-09-27 22:22:41 UTC · 0 stars

u20024804/bash-4.2-fixed-CVE-2014-6271

github · Created 2014-09-27 22:22:27 UTC · 0 stars

u20024804/bash-3.2-fixed-CVE-2014-6271

github · Created 2014-09-27 21:29:23 UTC · 0 stars

villadora/CVE-2014-6271

github · Created 2014-09-26 04:15:15 UTC · 0 stars

scaner for cve-2014-6271

woltage/CVE-2014-6271

github · Created 2014-09-25 13:06:50 UTC · 0 stars

ilismal/Nessus_CVE-2014-6271_check

github · Created 2014-09-25 09:02:42 UTC · 0 stars

Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271

mattclegg/CVE-2014-6271

github · Created 2014-09-25 08:10:26 UTC · 0 stars

jblaine/cookbook-bash-CVE-2014-6271

github · Created 2014-09-25 00:11:01 UTC · 0 stars

Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit