CVE-2014-7186 is a critical denial-of-service vulnerability affecting GNU Bash through version 4.3 bash43-026, stemming from an out-of-bounds array access due to crafted here documents. With a CVSS score of 10.0, this flaw is easily exploitable over the network with low complexity and no authentication, potentially leading to a complete system compromise (C:C/I:C/A:C). While not listed in CISA KEV, its high EPSS and FAUCET scores, along with significant community discussion and media coverage, indicate its severe risk. Although no Metasploit or Nuclei modules are available, related exploit code exists on ExploitDB, and it is frequently discussed in conjunction with other Shellshock vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.14.0CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.0:*:*:*:*:*:*:* | ||
1.14.1CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.1:*:*:*:*:*:*:* | ||
1.14.2CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.2:*:*:*:*:*:*:* | ||
1.14.3CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.3:*:*:*:*:*:*:* | ||
1.14.4CPE matchmatch criteria | cpe:2.3:a:gnu:bash:1.14.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.