Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-6278

98
FAUCET Score

CVE-2014-6278, known as "Shellshock," is a critical vulnerability in GNU Bash through version 4.3 that allows remote attackers to execute arbitrary commands due to improper parsing of function definitions in environment variables. This flaw, an incomplete fix for prior Bash vulnerabilities, carries a CVSS score of 8.8 (High) and enables unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. It is actively exploited in the wild, with numerous public exploits, Metasploit modules, and extensive community discussion and media coverage highlighting its widespread impact.

Impacted Technologies

VendorProductVersion(s)CPE
1.14.0CPE matchmatch criteria
cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:*
1.14.1CPE matchmatch criteria
cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:*
1.14.2CPE matchmatch criteria
cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:*
1.14.3CPE matchmatch criteria
cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:*
1.14.4CPE matchmatch criteria
cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
99.62%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Oct 2, 2025
Metasploit: Apache mod_cgi Bash Environment Variable Code Injection (Shellshock) · Sep 24, 2014
ExploitDB: EDB-39887 · Jun 6, 2016
This CVE's current EPSS score of 0.9962 is in the 100th percentile among its peer group of 14,855 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2014-6278

bash: incorrect parsing of function definitions with nested command substitutions

Sep 29, 2014

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
jvndb.jvn.jp / jvndb/JVNDB-2014-000126
Third Party Advisory
jvn.jp / en/jp/JVN55667175/index.html
Third Party Advisory
lcamtuf.blogspot.com / 2014/09/bash-bug-apply-unofficial-patch-now.html
PatchThird Party Advisory
lcamtuf.blogspot.com / 2014/10/bash-bug-how-we-finally-cracked.html
Third Party Advisory
linux.oracle.com / errata/ELSA-2014-3093
Third Party Advisory
linux.oracle.com / errata/ELSA-2014-3094
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-10/msg00004.html
Mailing List
lists.opensuse.org / opensuse-updates/2014-10/msg00025.html
Mailing List
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
packetstormsecurity.com / files/128567/CA-Technologies-GNU-Bash-Shellshock.html
Third Party Advisory
packetstormsecurity.com / files/137344/Sun-Secure-Global-Desktop-Oracle-Global-Desktop-Shellshock.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Third Party Advisory
secunia.com / advisories/58200
Broken Link
secunia.com / advisories/59907
Broken Link
secunia.com / advisories/59961
Broken Link
secunia.com / advisories/60024
Broken Link
secunia.com / advisories/60034
Broken Link
secunia.com / advisories/60044
Broken Link
secunia.com / advisories/60055
Broken Link
secunia.com / advisories/60063
Broken Link
secunia.com / advisories/60193
Broken Link
secunia.com / advisories/60325
Broken Link
secunia.com / advisories/60433
Broken Link
secunia.com / advisories/61065
Broken Link
secunia.com / advisories/61128
Broken Link
secunia.com / advisories/61129
Broken Link
secunia.com / advisories/61283
Broken Link
secunia.com / advisories/61287
Broken Link
secunia.com / advisories/61291
Broken Link
secunia.com / advisories/61312
Broken Link
secunia.com / advisories/61313
Broken Link
secunia.com / advisories/61328
Broken Link
secunia.com / advisories/61442
Broken Link
secunia.com / advisories/61471
Broken Link
secunia.com / advisories/61485
Broken Link
secunia.com / advisories/61503
Broken Link
secunia.com / advisories/61550
Broken Link
secunia.com / advisories/61552
Broken Link
secunia.com / advisories/61565
Broken Link
secunia.com / advisories/61603
Broken Link
secunia.com / advisories/61633
Broken Link
secunia.com / advisories/61641
Broken Link
secunia.com / advisories/61643
Broken Link
secunia.com / advisories/61654
Broken Link
secunia.com / advisories/61703
Broken Link
secunia.com / advisories/61780
Broken Link
secunia.com / advisories/61816
Broken Link
secunia.com / advisories/61857
Broken Link
secunia.com / advisories/62312
Broken Link
secunia.com / advisories/62343
Third Party Advisory
kb.bluecoat.com / index
Third Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
kc.mcafee.com / corporate/index
Third Party Advisory
security-tracker.debian.org / tracker/CVE-2014-6278
Third Party Advisory
supportcenter.checkpoint.com / supportcenter/portal
Third Party Advisory
support.citrix.com / article/CTX200217
Third Party Advisory
support.citrix.com / article/CTX200223
Third Party Advisory
support.f5.com / kb/en-us/solutions/public/15000/600/sol15629.html
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
support.novell.com / security/cve/CVE-2014-6278.html
Third Party Advisory
arista.com / en/support/advisories-notices/security-advisories/1008-security-advisory-0006
Third Party Advisory
exploit-db.com / exploits/39568
Third Party Advisory
exploit-db.com / exploits/39887
Third Party Advisory
suse.com / support/shellshock
Vendor Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-947.ibm.com / support/entry/portal/docdisplay
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
novell.com / support/kb/doc.php
Third Party Advisory
oracle.com / technetwork/topics/security/bashcve-2014-7169-2317675.html
Third Party Advisory
qnap.com / i/en/support/con_show.php
Third Party Advisory
ubuntu.com / usn/USN-2380-1
Third Party Advisory
vmware.com / security/advisories/VMSA-2014-0010.html
Third Party Advisory