Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-6271

99
FAUCET Score

CVE-2014-6271, known as "ShellShock," is a critical remote code execution vulnerability in GNU Bash through version 4.3, affecting numerous products including Apple, Red Hat, and Oracle. It allows attackers to execute arbitrary commands by injecting malicious code into environment variables, bypassing privilege boundaries. With a CVSS score of 9.8 (Critical), it poses a severe risk due to its network-based attack vector, low complexity, and complete compromise potential. This vulnerability is actively exploited, listed in CISA's KEV catalog, and has extensive public exploit code available, including Metasploit modules and Nuclei templates, leading to significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.3CPE matchmatch criteria
cpe:2.3:a:gnu:bash:*:*:*:*:*:*:*:*
>= 4.9.0, < 4.9.12CPE matchmatch criteria
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
>= 4.10.0, < 4.10.9CPE matchmatch criteria
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
>= 4.11.0, < 4.11.11CPE matchmatch criteria
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
>= 4.12.0, < 4.12.9CPE matchmatch criteria
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
100.00%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Added to KEV · Jan 28, 2022
Metasploit: CUPS Filter Bash Environment Variable Code Injection (Shellshock) · Sep 24, 2014
Nuclei: CVE-2014-6271 · Oct 1, 2020
ExploitDB: EDB-42938 · Oct 2, 2017
This CVE's current EPSS score of 1.0000 is in the 100th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4 Extended Lifecycle SupportFixed in: bash-0:3.0-27.el4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: bash-0:3.2-33.el5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 Long LifeFixed in: bash-0:3.2-24.el5_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Extended Update SupportFixed in: bash-0:3.2-32.el5_9.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: bash-0:4.1.2-15.el6_5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: bash-0:4.1.2-9.el6_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Extended Update SupportFixed in: bash-0:4.1.2-15.el6_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: bash-0:4.2.45-5.el7_0.2
View patch
redhatpatch availablevia redhat_api
Product: RHEV Manager version 3.4Fixed in: rhev-hypervisor6-0:6.5-20140930.1.el6ev
View patch
redhatpatch availablevia redhat_api
Product: S-JIS for Red Hat Enteprise Linux 5Fixed in: bash-0:3.2-33.el5_11.1.sjis.1
View patch
redhatpatch availablevia redhat_api
Product: S-JIS for Red Hat Enteprise Linux 6Fixed in: bash-0:4.1.2-15.el6_5.1.sjis.1
View patch
redhatpatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2014-6271Critical

bash: specially-crafted environment variables can be used to inject shell commands

Sep 24, 2014

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
advisories.mageia.org / MGASA-2014-0388.html
Third Party Advisory
archives.neohapsis.com / archives/bugtraq/2014-10/0101.html
Broken LinkThird Party Advisory
jvndb.jvn.jp / jvndb/JVNDB-2014-000126
Third Party AdvisoryVDB EntryVendor Advisory
jvn.jp / en/jp/JVN55667175/index.html
Vendor Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
lcamtuf.blogspot.com / 2014/09/quick-notes-about-bash-bug-its-impact.html
ExploitIssue TrackingThird Party Advisory
linux.oracle.com / errata/ELSA-2014-1293.html
Third Party Advisory
linux.oracle.com / errata/ELSA-2014-1294.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00028.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00029.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00034.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00037.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00040.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00044.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-09/msg00049.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-10/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2014-10/msg00023.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2014-10/msg00025.html
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
packetstormsecurity.com / files/128517/VMware-Security-Advisory-2014-0010.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/128567/CA-Technologies-GNU-Bash-Shellshock.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/128573/Apache-mod_cgi-Remote-Command-Execution.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/161107/SonicWall-SSL-VPN-Shellshock-Remote-Code-Execution.html
Third Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2014-1293.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-1294.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-1295.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-1354.html
Third Party Advisory
access.redhat.com / articles/1200223
ExploitThird Party Advisory
access.redhat.com / node/1200223
ExploitThird Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatch
seclists.org / fulldisclosure/2014/Oct/0
Mailing ListThird Party Advisory
secunia.com / advisories/58200
Broken LinkThird Party Advisory
secunia.com / advisories/59272
Broken LinkThird Party Advisory
secunia.com / advisories/59737
Broken LinkThird Party Advisory
secunia.com / advisories/59907
Broken LinkThird Party Advisory
secunia.com / advisories/60024
Broken LinkThird Party Advisory
secunia.com / advisories/60034
Broken LinkThird Party Advisory
secunia.com / advisories/60044
Broken LinkThird Party Advisory
secunia.com / advisories/60055
Broken LinkThird Party Advisory
secunia.com / advisories/60063
Broken LinkThird Party Advisory
secunia.com / advisories/60193
Broken LinkThird Party Advisory
secunia.com / advisories/60325
Broken LinkThird Party Advisory
secunia.com / advisories/60433
Broken LinkThird Party Advisory
secunia.com / advisories/60947
Broken LinkThird Party Advisory
secunia.com / advisories/61065
Broken LinkThird Party Advisory
secunia.com / advisories/61128
Broken LinkThird Party Advisory
secunia.com / advisories/61129
Broken LinkThird Party Advisory
secunia.com / advisories/61188
Broken LinkThird Party Advisory
secunia.com / advisories/61283
Broken LinkThird Party Advisory
secunia.com / advisories/61287
Broken LinkThird Party Advisory
secunia.com / advisories/61291
Broken LinkThird Party Advisory
secunia.com / advisories/61312
Broken LinkThird Party Advisory
secunia.com / advisories/61313
Broken LinkThird Party Advisory
secunia.com / advisories/61328
Broken LinkThird Party Advisory
secunia.com / advisories/61442
Broken LinkThird Party Advisory
secunia.com / advisories/61471
Broken LinkThird Party Advisory
secunia.com / advisories/61485
Broken LinkThird Party Advisory
secunia.com / advisories/61503
Broken LinkThird Party Advisory
secunia.com / advisories/61542
Broken LinkThird Party Advisory
secunia.com / advisories/61547
Broken LinkThird Party Advisory
secunia.com / advisories/61550
Broken LinkThird Party Advisory
secunia.com / advisories/61552
Broken LinkThird Party Advisory
secunia.com / advisories/61565
Broken LinkThird Party Advisory
secunia.com / advisories/61603
Broken LinkThird Party Advisory
secunia.com / advisories/61633
Broken LinkThird Party Advisory
secunia.com / advisories/61641
Broken LinkThird Party Advisory
secunia.com / advisories/61643
Broken LinkThird Party Advisory
secunia.com / advisories/61654
Broken LinkThird Party Advisory
secunia.com / advisories/61676
Broken LinkThird Party Advisory
secunia.com / advisories/61700
Broken LinkThird Party Advisory
secunia.com / advisories/61703
Broken LinkThird Party Advisory
secunia.com / advisories/61711
Broken LinkThird Party Advisory
secunia.com / advisories/61715
Broken LinkThird Party Advisory
secunia.com / advisories/61780
Broken LinkThird Party Advisory
secunia.com / advisories/61816
Broken LinkThird Party Advisory
secunia.com / advisories/61855
Broken LinkThird Party Advisory
secunia.com / advisories/61857
Broken LinkThird Party Advisory
secunia.com / advisories/61873
Broken LinkThird Party Advisory
secunia.com / advisories/62228
Broken LinkThird Party Advisory
secunia.com / advisories/62312
Broken LinkThird Party Advisory
secunia.com / advisories/62343
Broken LinkThird Party Advisory
help.ecostruxureit.com / display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
Broken LinkThird Party Advisory
kb.bluecoat.com / index
Broken LinkThird Party Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
kc.mcafee.com / corporate/index
Broken LinkThird Party Advisory
securityblog.redhat.com / 2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack
ExploitThird Party Advisory
support.apple.com / kb/HT6535
Third Party Advisory
supportcenter.checkpoint.com / supportcenter/portal
Third Party Advisory
support.citrix.com / article/CTX200217
Third Party Advisory
support.citrix.com / article/CTX200223
Permissions Required
support.f5.com / kb/en-us/solutions/public/15000/600/sol15629.html
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Broken LinkThird Party Advisory
support.apple.com / kb/HT6495
Third Party Advisory
support.novell.com / security/cve/CVE-2014-6271.html
Third Party Advisory
arista.com / en/support/advisories-notices/security-advisories/1008-security-advisory-0006
Third Party Advisory
exploit-db.com / exploits/34879
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/37816
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/38849
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/39918
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/40619
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/40938
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/42938
ExploitThird Party AdvisoryVDB Entry
suse.com / support/shellshock
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Broken LinkThird Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Broken LinkThird Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-947.ibm.com / support/entry/portal/docdisplay
Broken LinkThird Party Advisory
debian.org / security/2014/dsa-3032
Mailing ListThird Party Advisory
kb.cert.org / vuls/id/252743
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Broken LinkThird Party Advisory
novell.com / support/kb/doc.php
Third Party Advisory
novell.com / support/kb/doc.php
Third Party Advisory
oracle.com / technetwork/topics/security/bashcve-2014-7169-2317675.html
Third Party Advisory
qnap.com / i/en/support/con_show.php
Third Party Advisory
securityfocus.com / archive/1/533593/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/70103
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2362-1
Third Party Advisory
us-cert.gov / ncas/alerts/TA14-268A
Third Party AdvisoryUS Government Resource
vmware.com / security/advisories/VMSA-2014-0010.html
Third Party Advisory
websense.com / support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
Broken LinkThird Party Advisory