Skip to main content

CVE detail

CVE-2014-6271

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

CVSS 9.8 · CriticalBuzz score 83.6KEV listed2 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 83.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 11.1
Mention score
30.0
36 evidence mentions in the snapshot
Diversity score
17.5
7 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
11.1
2 repos · best confidence 0.99
Best PoC traction
1
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
36 source links · newest first
  • The Convergence of Cloud Secrets & AI RiskSentinelOne Labs

    initial access points. The top verified exploit paths continue to involve older, critical CVEs, including: Shellshock ( CVE-2014-6271 ) FortiGate SSL VPN credential disclosure ( CVE-2018-13379 ) Pulse Secure VPN arbitrary file read ( CVE-2019-11510 ) Webmin RCE ( CVE-2019-15107 ) Barracuda ESG zero-day backdoor ( CVE-2023-1698 ) Since these vulnerabil

    vendorwww.sentinelone.comMay 13, 2026, 6:11 PM
  • RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, CCTV systems, and servers, active globally since June. Trend Micro researchers reported that the RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, NVRs, CCTV systems, and web servers, active globally since June. Experts noted that the latest […]

    newssecurityaffairs.comOct 10, 2025, 7:33 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Smartbedded Meteobridge, Samsung, Juniper ScreenOS, Jenkins, and GNU Bash flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these […]

    newssecurityaffairs.comOct 4, 2025, 3:49 PM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week announced the addition of eight more vulnerabilities to the list of security flaws known to be exploited in malicious attacks.

    newswww.securityweek.comFeb 1, 2022, 11:12 AM
  • The US CISA added eight more flaws to its Known Exploited Vulnerabilities Catalog that are known to be used in attacks in the wild. The US Cybersecurity & Infrastructure Security Agency (CISA) has added eight more flaws to the Known Exploited Vulnerabilities Catalog. The ‘Known Exploited Vulnerabilities Catalog‘ is a list of known vulnerabilities that […]

    newssecurityaffairs.comJan 31, 2022, 9:05 PM
  • Organizations in the financial and insurance sectors were the most targeted by threat actors in 2020, continuing a trend that was first observed roughly five years ago, IBM Security reports.

    newswww.securityweek.comApr 2, 2021, 12:42 PM
  • Released in March 2020, the Cyberspace Solarium Commission’s report urges for the U.S. government and private sector to adopt a “new, strategic approach to cybersecurity,” namely layered cyber deterrence. Among the Commission’s lengthy 182-page report’s recommendations are that security vendors must be responsible for providing security updates for their products or services as long as they are providing usability updates and bug fixes. Additionally, the report calls for Congress to “pass a law establishing that … More →

    newswww.helpnetsecurity.comJul 9, 2020, 4:30 AM
  • Crooks are attempting to exploit a recently patched Drupal vulnerability, tracked as CVE-2018-7602, to drop Monero mining malware onto vulnerable systems. The CVE-2018-7602 flaw is a highly critical remote code execution issue, also known as Drupalgeddon3, that was addressed by the Drupal team in April with the release of versions 7.59, 8.4.8 and 8.5.3. The security patch for the […]

    newssecurityaffairs.comJun 22, 2018, 5:19 PM
  • Network attacks exploiting a recently patched Drupal vulnerability are attempting to drop Monero mining malware onto vulnerable systems, Trend Micro reports.

    newswww.securityweek.comJun 22, 2018, 12:21 PM
  • Rudimentary attacks, such as intrusion attempts, information gathering, and policy violations pose the greatest risk to midsized organizations, according to eSentire. Attacks per type heat map “In 2016, the eSentire SOC detected almost 5 million attacks across hundreds of primarily small to medium organizations, spanning multiple industries,” said Viktors Engelbrehts, director of threat intelligence at eSentire. “Cybercriminals are attracted to easy targets because they are low risk, high reward, and require little effort to execute. … More →

    newswww.helpnetsecurity.comMay 8, 2017, 12:55 PM
  • Two and a half years after being discovered, the Shellshock vulnerability continues to be abused in attacks, and for a good reason: it is a very cheap and easy attack, IBM says.

    newswww.securityweek.comMar 6, 2017, 6:13 PM
  • Top Cybersecurity Headlines of 2014SecurityWeek

    Data breaches, dangerous vulnerabilities and more dominated the headlines this year in cybersecurity.

    newswww.securityweek.comDec 30, 2014, 10:10 PM
  • ShellShock, the remote code execution bug (CVE-2014-6271) affecting GNU Bash, the command interpreter present on many Unix systems and Linux distributions, is still being exploited by attackers. Trend Micro threat response engineer Rhena Inocencio warns about attackers leveraging a new version of the Bashlite malware, which was initially created as a DDoS bot with brute forcing capabilities and exploits the ShellShock bug. The malware now targets both computers and other devices running on BusyBox, located … More →

    newswww.helpnetsecurity.comNov 17, 2014, 11:30 AM
  • It appears that 2014 will be remembered in the IT industry for several severe and wide-reaching server-side vulnerabilities. In April, a serious flaw ( CVE-2014-0160 ) in the widely-used OpenSSL encryption software that protects website traffic shook the industry (a.k.a. Heartbleed), leaving hundreds of thousands of systems open to attacks from cybercriminals. More than six months later, thousands of websites and devices still remain vulnerable . In September, multiple critical vulnerabilities ( CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE 2014-6278 ) were reported in the GNU Bourne-Again Shell (Bash), the common command-line shell used in many Linux / UNIX operating systems and Apple’s Mac OS X. The flaws could allow an attacker to remotely execute shell commands by attaching malicious code in environment variables used by the operating system. Similar to Heartbleed, these flaws affect a broad range of systems, including but not limited to Apache…

    newswww.securityweek.comNov 5, 2014, 3:18 PM
  • The GNU Bash vulnerability dubbed ShellShock affects a wide range of software solutions, including some industrial products developed by the German engineering and electronics giant Siemens.

    newswww.securityweek.comOct 8, 2014, 6:47 PM
  • The security researcher Michal Zalewski revealed the details of other two additional bugs he discovered in the Bourne Again Shell after the Bash Bug case. IT community worldwide has been shocked by the discovery of the Bash Bug flaw, a vulnerability that was present in the popular Bash component for more than two decades. While principal […]

    newssecurityaffairs.comOct 5, 2014, 1:28 PM
  • Joining several major tech companies, VMware has started rolling out software updates that address the recently discovered GNU Bash vulnerability dubbed ShellShock.

    newswww.securityweek.comOct 2, 2014, 1:41 PM
  • Researchers have discovered hackers trying to exploit the Shellshock Bash vulnerability to compromise network attached storage devices in universities in the U.S., Japan and Korea. The attackers were taking advantage of a publicly disclosed security weakness in which the web servers embedded in the devices manufactured by QNAP have administrative privileges by default, researchers for […]

    newswww.csoonline.comOct 1, 2014, 11:43 PM
  • Ever since the existence of the GNU Bash flaw ( Shellshock ) came to light last week, threat actors have been searching for vulnerable machines that they can exploit for various purposes, Incapsula said on Monday.

    newswww.securityweek.comSep 30, 2014, 9:42 AM
  • Apple patches Shellshock bug in OS XHelp Net Security

    Apple has finally released a security update for OS X that will close up the critical remote code execution Shellshock bug found in the GNU Bash UNIX shell. The update resolves both the CVE-2014-6271 issue discovered by Stephane Chazelas, as well as the CVE-2014-7169 one flagged by Tavis Ormandy. Security updates have been provided for OS X Mavericks, Mountain Lion, and Lion users. According to Ars Technica, the patch will not be provided for current … More →

    newswww.helpnetsecurity.comSep 30, 2014, 4:54 AM
  • The number of attempts by hackers to compromise computers through the Shellshock vulnerability is rising, but companies have options for defending against attackers. Shellshock is the name given to a set of at least six vulnerabilities in GNU Bash, the default command shell found in Linux, Unix and Mac OS X. The flaws in Bash, […]

    newswww.csoonline.comSep 30, 2014, 12:58 AM
  • Several organizations that use the GNU Bourne Again Shell (Bash) in their products have been hard at work producing software updates to address the recently discovered vulnerability dubbed “ Shellshock ” or “Bash Bug.” GNU Bash is a command-line shell used in Linux, Unix and Mac OS X operating systems which is installed not only on personal computers and servers, but also installed on other connected “Internet of Things” (IoT) devices. The vulnerability ( CVE-2014-6271 ) affects version 1.14 and later of the shell and can be exploited to execute arbitrary commands and take over affected machines. Red Hat published a security update shortly after the existence of Shellshock came to light. However, it soon became clear that the fix had been incomplete since, according to Red Hat, “Bash still allowed certain characters to be injected into other environments via specially crafted environment variables.” This second issue has been assigned CVE-2014-7169 . On Friday, both Red Hat and Fedora…

    newswww.securityweek.comSep 29, 2014, 11:22 AM
  • From Thursday on, several security firms reported a drastic uptick in the number of attacks that leverage the recently disclosed vulnerability in GNU Bash (CVE-2014-6271), widely known as Shellshock. On Friday, AlienVault labs reported that the flaw was being used by two attackers to install two different pieces of malware on the victim system. One […]

    newswww.csoonline.comSep 29, 2014, 11:00 AM
  • ShellShock could be used to hack VoIP systemsSecurity Affairs

    Jaime Blasco at AlienVault Labs explained that ShellShock vulnerability could be exploited to hack Voice over IP systems worldwide. The Shellshock Bash is monopolizing the debate on the Internet security in these days, every vendor is assessing its product to verify the impact of the critical vulnerability Bash Bug (CVE-2014-6271). Apple recently announced that its Mac OS X based […]

    newssecurityaffairs.comSep 28, 2014, 11:52 AM
  • The existence of a highly critical vulnerability affecting the GNU Bourne Again Shell (Bash) has been brought to light this week. The security flaw is considered by some members of the industry as being worse than the notorious Heartbleed bug.

    newswww.securityweek.comSep 26, 2014, 5:12 PM
  • The recently disclosed “Bash Bug” or “Shellshock” vulnerability that affects most versions of Linux, Unix, and Mac OS X operating systems is the latest threat to set IT security teams scrambling to protect their systems.

    newswww.securityweek.comSep 26, 2014, 11:56 AM
  • Bash “Shellshock” bug: Who needs to worry?Help Net Security

    As expected, attackers have begun exploiting the GNU Bash “Shellshock” remote code execution bug (CVE-2014-6271) to compromise systems and infect them with malware. After the disclosure of its existence, Alien Vault has begun running a new module in their honeypots and waiting for attackers aiming to exploit this vulnerability. “We have had several hits in the last 24 hours. Most of them are systems trying to detect if the system is vulnerable and they simple … More →

    newswww.helpnetsecurity.comSep 26, 2014, 8:49 AM
  • The critical vulnerability Bash Bug in common GNU shell could be exploited by botmaster to infect a huge number of machines on a large scale. The recently discovered Bash Bug vulnerability, coded as CVE-2014-6271 and known also as “Shellshock,” is worrying the security community due to its impact on a large-scale. The remotely exploitable critical flaw affects Linux, Unix and […]

    newssecurityaffairs.comSep 26, 2014, 6:00 AM
  • Beating back the recently disclosed GNU Bourne Again Shell (Bash) vulnerability may not be as easy as some hoped.

    newswww.securityweek.comSep 25, 2014, 11:09 PM
  • Around 6:00 am PST on September 24, the details of a vulnerability in the widely used Bourne Again Shell (Bash) were disclosed by multiple Linux vendors. The vulnerability, assigned CVE-2014-6271 by Mitre, was originally discovered by Stephane Chazelas, a Unix and Linux network and telecom administrator and IT manager at UK robotics company SeeByte, Ltd.

    vendorunit42.paloaltonetworks.comSep 25, 2014, 2:32 PM
  • Bash Bug is a critical flaw remotely Exploitable which affects Linux, Unix and Apple Mac OS X and that is threatening the global Internet infrastructure. A new critical vulnerability dubbed Bash Bug in Linux and Unix command-line shell, aka the GNU Bourne Again Shell, is threatening the IT world. The flaw, coded as CVE-2014-6271, is remotely exploitable and affects Linux […]

    newssecurityaffairs.comSep 25, 2014, 9:38 AM
  • The Bash “shellshock” flaw (CVE-2014-6271) was discovered last week by Unix/Linux specialist Stephane Chazelas, and its existence was made public on Wednesday. It affects Bash, the command interpreter present on many Unix systems and systems based on it: various Linux distributions and Apple’s OS X. It can be exploited by attackers looking to override or bypass environment restrictions to execute shell commands, i.e. unauthorized, malicious code. The flaw is deemed critical for many reasons. For … More →

    newswww.helpnetsecurity.comSep 25, 2014, 8:20 AM
  • A vulnerability (CVE-2014-6271) has been discovered in the GNU Bourne Again Shell (bash) that can be exploited to execute code.

    newswww.securityweek.comSep 24, 2014, 11:24 PM
  • Update (12:34 PM): Web security firm Sucuri has already detected in the wild attempts to load remote shells onto servers using…

    newswww.malwarebytes.comSep 24, 2014, 5:00 PM
  • A remotely exploitable vulnerability has been discovered by Stephane Chazelas in bash on Linux and it is unpleasant. The vulnerability has the CVE identifier CVE-2014-6271 and has been given the name Shellshock by some. This affects Debian as well as other Linux distributions. You will need to patch ASAP. Bash supports exporting shell variables as well […]

    newswww.csoonline.comSep 24, 2014, 3:35 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

2 repository references · best confidence 0.99 · max 1 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence