CVE-2014-6278
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)
by lastc0de · Jun 6, 2016
Cisco UCS Manager 2.1(1b) - Remote Command Injection (Shellshock)
by thatchriseckert · Mar 16, 2016
GNU bash 4.3.11 - Environment Variable dhclient
by @0x00string · Oct 2, 2014
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
by fdiskyou · Sep 29, 2014
Apache mod_cgi - 'Shellshock' Remote Command Injection
by Federico Galatolo · Oct 6, 2014
Frequently Asked Questions
Is CVE-2014-6278 in your stack?
O3 detects CVE-2014-6278 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.