Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2022-01-28 — agencies required to remediate by 2022-07-28

CVE-2014-7169

CRITICAL
Published
Sep 25, 2014
Updated
Apr 16, 2026
Affected
0 pkgs
Patched
None yet
Exploits
21 known

EPSS Exploitation Probability

via FIRST.org ↗
89.1%probability of exploitation in next 30 days
Very High Risk100th percentile0.00%
88.6%89.2%89.9%90.6%89.6%89.1%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

Exploits & PoCs
21

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-34839webappscgi✓ Verified

IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection

by Claudio Viviani · Oct 1, 2014

EDB-35115remotelinux✓ Verified

CUPS Filter - Bash Environment Variable Code Injection (Metasploit)

by Metasploit · Oct 29, 2014

EDB-34765remotelinux✓ Verified

GNU Bash - 'Shellshock' Environment Variable Command Injection

by Stephane Chazelas · Sep 25, 2014

EDB-36609webappsmultiple

Kemp Load Master 7.1.16 - Multiple Vulnerabilities

by Roberto Suggi Liverani · Apr 2, 2015

EDB-34766remotelinux✓ Verified

Bash - 'Shellshock' Environment Variables Command Injection

by Prakhar Prasad & Subho Halder · Sep 25, 2014

EDB-36503remotehardware

QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)

by Patrick Pellegrino · Mar 26, 2015

EDB-34860remotelinux

GNU bash 4.3.11 - Environment Variable dhclient

by @0x00string · Oct 2, 2014

EDB-34895webappscgi✓ Verified

Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)

by Fady Mohammed Osman · Oct 6, 2014

EDB-35146webappsphp

PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection

by Ryan King (Starfall) · Nov 3, 2014

EDB-34896remotelinux✓ Verified

Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection

by Phil Blank · Oct 6, 2014

Frequently Asked Questions

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an i
O3 Security · Impact-Aware SCA

Is CVE-2014-7169 in your stack?

O3 detects CVE-2014-7169 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.