CVE-2014-6278, known as "Shellshock," is a critical vulnerability in GNU Bash through version 4.3 that allows remote attackers to execute arbitrary commands due to improper parsing of function definitions in environment variables. This flaw, an incomplete fix for prior Bash vulnerabilities, carries a CVSS score of 8.8 (High) and enables unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. It is actively exploited in the wild, with numerous public exploits, Metasploit modules, and extensive community discussion and media coverage highlighting its widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14.0CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:* | ||
1.14.1CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:* | ||
1.14.2CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:* | ||
1.14.3CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:* | ||
1.14.4CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.