Critical Alert 1 Active Exploit Detected Today

CVE-2026-104286 — Fortinet FortiMail Path Traversal Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2014-6271NVD

Vulnerability Summary

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Severity Level
CRITICAL(9.8)
Published Date
Sep 24, 2014
Last Modified
Apr 22, 2026
PoC
Available(Metasploit, Nuclei)
Exploitation Status
ACTIVE
EPSS Score (30-Day)
94.22%Probability
Root Weakness (CWE)
N/A
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

Affected & Patched Versions

Affected Versions
  • Gnu Bash <= 4.3
  • Arista Eos >= 4.9.0 and < 4.9.12
  • Arista Eos >= 4.10.0 and < 4.10.9
  • Arista Eos >= 4.11.0 and < 4.11.11
  • Arista Eos >= 4.12.0 and < 4.12.9
  • Arista Eos >= 4.13.0 and < 4.13.9
  • Arista Eos >= 4.14.0 and < 4.14.4f
  • Oracle Linux
  • Qnap Qts < 4.1.1
  • Qnap Qts
  • Mageia Mageia
  • Redhat Gluster Storage Server For On-premise
  • Redhat Virtualization
  • Redhat Enterprise Linux
  • Redhat Enterprise Linux Desktop
  • Redhat Enterprise Linux Eus
  • Redhat Enterprise Linux For Ibm Z Systems
  • Redhat Enterprise Linux For Power Big Endian
  • Redhat Enterprise Linux For Power Big Endian Eus
  • Redhat Enterprise Linux For Scientific Computing
  • Redhat Enterprise Linux Server
  • Redhat Enterprise Linux Server Aus
  • Redhat Enterprise Linux Server From Rhui
  • Redhat Enterprise Linux Server Tus
  • Redhat Enterprise Linux Workstation
  • Suse Studio Onsite
  • Opensuse Opensuse
  • Suse Linux Enterprise Desktop
  • Suse Linux Enterprise Server
  • Suse Linux Enterprise Software Development Kit
  • Debian Debian Linux
  • Ibm Infosphere Guardium Database Activity Monitoring
  • Ibm Pureapplication System >= 1.0.0.0 and <= 1.0.0.4
  • Ibm Pureapplication System >= 1.1.0.0 and <= 1.1.0.4
  • Ibm Pureapplication System
  • Ibm Qradar Risk Manager
  • Ibm Qradar Security Information And Event Manager
  • Ibm Qradar Vulnerability Manager
  • Ibm Smartcloud Entry Appliance
  • Ibm Smartcloud Provisioning
  • Ibm Software Defined Network For Virtual Environments < 1.2.1
  • Ibm Starter Kit For Cloud
  • Ibm Workload Deployer >= 3.1.0 and <= 3.1.0.7
  • Ibm Security Access Manager For Mobile 8.0 Firmware
  • Ibm Security Access Manager For Web 7.0 Firmware
  • Ibm Security Access Manager For Web 8.0 Firmware
  • Ibm Storwize V7000 Firmware >= 1.1.0.0 and < 1.4.3.5
  • Ibm Storwize V7000 Firmware >= 1.5.0.0 and < 1.5.0.4
  • Ibm Storwize V7000 Firmware >= 7.2.0.0 and < 7.2.0.9
  • Ibm Storwize V7000 Firmware >= 7.3.0.0 and < 7.3.0.7
  • Ibm Storwize V5000 Firmware >= 1.1.0.0 and < 7.1.0.11
  • Ibm Storwize V5000 Firmware >= 7.2.0.0 and < 7.2.0.9
  • Ibm Storwize V5000 Firmware >= 7.3.0.0 and < 7.3.0.7
  • Ibm Storwize V3700 Firmware >= 1.1.0.0 and < 7.1.0.11
  • Ibm Storwize V3700 Firmware >= 7.2.0.0 and < 7.2.0.9
  • Ibm Storwize V3700 Firmware >= 7.3.0.0 and < 7.3.0.7
  • Ibm Storwize V3500 Firmware >= 1.1.0.0 and < 7.1.0.11
  • Ibm Storwize V3500 Firmware >= 7.2.0.0 and < 7.2.0.9
  • Ibm Storwize V3500 Firmware >= 7.3.0.0 and < 7.3.0.7
  • Ibm Flex System V7000 Firmware >= 1.1.0.0 and < 7.1.0.11
  • Ibm Flex System V7000 Firmware >= 7.2.0.0 and < 7.2.0.9
  • Ibm Flex System V7000 Firmware >= 7.3.0.0 and < 7.3.0.7
  • Ibm San Volume Controller Firmware >= 1.1.0.0 and < 7.1.0.11
  • Ibm San Volume Controller Firmware >= 7.2.0.0 and < 7.2.0.9
  • Ibm San Volume Controller Firmware >= 7.3.0.0 and < 7.3.0.7
  • Ibm Stn6500 Firmware >= 3.8.0.0 and < 3.8.0.07
  • Ibm Stn6500 Firmware >= 3.9.1.0 and < 3.9.1.08
  • Ibm Stn6500 Firmware >= 4.1.2.0 and < 4.1.2.06
  • Ibm Stn6800 Firmware >= 3.8.0.0 and < 3.8.0.07
  • Ibm Stn6800 Firmware >= 3.9.1.0 and < 3.9.1.08
  • Ibm Stn6800 Firmware >= 4.1.2.0 and < 4.1.2.06
  • Ibm Stn7800 Firmware >= 3.8.0.0 and < 3.8.0.07
  • Ibm Stn7800 Firmware >= 3.9.1.0 and < 3.9.1.08
  • Ibm Stn7800 Firmware >= 4.1.2.0 and < 4.1.2.06
  • Canonical Ubuntu Linux
  • Novell Zenworks Configuration Management
  • Novell Open Enterprise Server
  • Checkpoint Security Gateway < r77.30
  • F5 Big-ip Access Policy Manager >= 10.1.0 and <= 10.2.4
  • F5 Big-ip Access Policy Manager >= 11.0.0 and <= 11.5.1
  • F5 Big-ip Access Policy Manager
  • F5 Big-ip Advanced Firewall Manager >= 11.3.0 and <= 11.5.1
  • F5 Big-ip Advanced Firewall Manager
  • F5 Big-ip Analytics >= 11.0.0 and <= 11.5.1
  • F5 Big-ip Analytics
  • F5 Big-ip Application Acceleration Manager >= 11.4.0 and <= 11.5.1
  • F5 Big-ip Application Acceleration Manager
  • F5 Big-ip Application Security Manager >= 10.0.0 and <= 10.2.4
  • F5 Big-ip Application Security Manager >= 11.0.0 and <= 11.5.1
  • F5 Big-ip Application Security Manager
  • F5 Big-ip Edge Gateway >= 10.1.0 and <= 10.2.4
  • F5 Big-ip Edge Gateway >= 11.0.0 and <= 11.3.0
  • F5 Big-ip Global Traffic Manager >= 10.0.0 and <= 10.2.4
  • F5 Big-ip Global Traffic Manager >= 11.0.0 and <= 11.5.1
  • F5 Big-ip Global Traffic Manager
  • F5 Big-ip Link Controller >= 10.0.0 and <= 10.2.4
  • F5 Big-ip Link Controller >= 11.0.0 and <= 11.5.1
  • F5 Big-ip Link Controller
  • F5 Big-ip Local Traffic Manager >= 10.0.0 and <= 10.2.4
  • F5 Big-ip Local Traffic Manager >= 11.0.0 and <= 11.5.1
  • F5 Big-ip Local Traffic Manager
  • F5 Big-ip Policy Enforcement Manager >= 11.3.0 and <= 11.5.1
  • F5 Big-ip Policy Enforcement Manager
  • F5 Big-ip Protocol Security Module >= 10.0.0 and <= 10.2.4
  • F5 Big-ip Protocol Security Module >= 11.0.0 and <= 11.4.1
  • F5 Big-ip Wan Optimization Manager >= 10.0.0 and <= 10.2.4
  • F5 Big-ip Wan Optimization Manager >= 11.0.0 and <= 11.3.0
  • F5 Big-ip Webaccelerator >= 10.0.0 and <= 10.2.4
  • F5 Big-ip Webaccelerator >= 11.0.0 and <= 11.3.0
  • F5 Big-iq Cloud >= 4.0.0 and <= 4.4.0
  • F5 Big-iq Device >= 4.2.0 and <= 4.4.0
  • F5 Big-iq Security >= 4.0.0 and <= 4.4.0
  • F5 Enterprise Manager >= 2.1.0 and <= 2.3.0
  • F5 Enterprise Manager >= 3.0.0 and <= 3.1.1
  • F5 Traffix Signaling Delivery Controller >= 4.0.0 and <= 4.0.5
  • F5 Traffix Signaling Delivery Controller
  • F5 Arx Firmware >= 6.0.0 and <= 6.4.0
  • Citrix Netscaler Sdx Firmware < 9.3.67.5r1
  • Citrix Netscaler Sdx Firmware >= 10 and < 10.1.129.11r1
  • Citrix Netscaler Sdx Firmware >= 10.5 and < 10.5.52.11r1
  • Apple Mac Os X >= 10.0.0 and < 10.10.0
  • Vmware Vcenter Server Appliance
  • Vmware Esx
Patched Versions
  • Arista Eos 4.9.12
  • Arista Eos 4.10.9
  • Arista Eos 4.11.11
  • Arista Eos 4.12.9
  • Arista Eos 4.13.9
  • Arista Eos 4.14.4f
  • Qnap Qts 4.1.1
  • Ibm Software Defined Network For Virtual Environments 1.2.1
  • Ibm Storwize V7000 Firmware 1.4.3.5
  • Ibm Storwize V7000 Firmware 1.5.0.4
  • Ibm Storwize V7000 Firmware 7.2.0.9
  • Ibm Storwize V7000 Firmware 7.3.0.7
  • Ibm Storwize V5000 Firmware 7.1.0.11
  • Ibm Storwize V5000 Firmware 7.2.0.9
  • Ibm Storwize V5000 Firmware 7.3.0.7
  • Ibm Storwize V3700 Firmware 7.1.0.11
  • Ibm Storwize V3700 Firmware 7.2.0.9
  • Ibm Storwize V3700 Firmware 7.3.0.7
  • Ibm Storwize V3500 Firmware 7.1.0.11
  • Ibm Storwize V3500 Firmware 7.2.0.9
  • Ibm Storwize V3500 Firmware 7.3.0.7
  • Ibm Flex System V7000 Firmware 7.1.0.11
  • Ibm Flex System V7000 Firmware 7.2.0.9
  • Ibm Flex System V7000 Firmware 7.3.0.7
  • Ibm San Volume Controller Firmware 7.1.0.11
  • Ibm San Volume Controller Firmware 7.2.0.9
  • Ibm San Volume Controller Firmware 7.3.0.7
  • Ibm Stn6500 Firmware 3.8.0.07
  • Ibm Stn6500 Firmware 3.9.1.08
  • Ibm Stn6500 Firmware 4.1.2.06
  • Ibm Stn6800 Firmware 3.8.0.07
  • Ibm Stn6800 Firmware 3.9.1.08
  • Ibm Stn6800 Firmware 4.1.2.06
  • Ibm Stn7800 Firmware 3.8.0.07
  • Ibm Stn7800 Firmware 3.9.1.08
  • Ibm Stn7800 Firmware 4.1.2.06
  • Checkpoint Security Gateway r77.30
  • Citrix Netscaler Sdx Firmware 9.3.67.5r1
  • Citrix Netscaler Sdx Firmware 10.1.129.11r1
  • Citrix Netscaler Sdx Firmware 10.5.52.11r1
  • Apple Mac Os X 10.10.0
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.

External References