CVE-2014-6271, known as "ShellShock," is a critical remote code execution vulnerability in GNU Bash through version 4.3, affecting numerous products including Apple, Red Hat, and Oracle. It allows attackers to execute arbitrary commands by injecting malicious code into environment variables, bypassing privilege boundaries. With a CVSS score of 9.8 (Critical), it poses a severe risk due to its network-based attack vector, low complexity, and complete compromise potential. This vulnerability is actively exploited, listed in CISA's KEV catalog, and has extensive public exploit code available, including Metasploit modules and Nuclei templates, leading to significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3CPE matchmatch criteria | cpe:2.3:a:gnu:bash:*:*:*:*:*:*:*:* | ||
>= 4.9.0, < 4.9.12CPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.10.0, < 4.10.9CPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.11.0, < 4.11.11CPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.12.0, < 4.12.9CPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.