Skip to content
COOEY

EXPOSURES › CVE-2014-6271

CVE-2014-6271

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-6271 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

A remote code execution flaw in GNU Bash allowed attackers to execute arbitrary code via environment variables in versions 4.3 and earlier.

GNU Bash through 4.3 failed to properly process trailing strings after function definitions in environment variables, enabling remote attackers to execute arbitrary code. DIB organizations must care because this unpatched vulnerability was actively exploited in the wild, leading to potential system compromise and data exfiltration. Organizations should ensure they are running patched versions of Bash and have robust patch management protocols to prevent exploitation of known CVEs.

Shame score — This is a foundational, long-standing vulnerability in a ubiquitous system tool that was actively exploited in the wild, representing a severe failure of patch management and version control.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.