CVE-2014-7169
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Description
CVE-2014-7169 is a CRITICAL OS command injection vulnerability (CWE-78) in GNU Bash through version 4.3, representing an incomplete fix for the original Shellshock vulnerability (CVE-2014-6271). The initial patch for CVE-2014-6271 did not fully address the underlying parsing flaw, allowing attackers to continue executing arbitrary commands through specially crafted environment variable values using alternative injection techniques. With a CVSS 3.1 score of 9.8, this vulnerability shares the same devastating impact characteristics as its predecessor: network-exploitable, no authentication required, no user interaction needed, and affecting virtually every Unix/Linux system running Bash. CISA added CVE-2014-7169 to its KEV catalog on January 28, 2022, with a remediation deadline of July 28, 2022. The EPSS score of 0.90108 (99.59th percentile) confirms extremely high exploitation activity.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| gnu | bash | <= 4.3 |
| arista | eos | >= 4.9.0, < 4.9.12; >= 4.10.0, < 4.10.9; >= 4.11.0, < 4.11.11; >= 4.12.0, < 4.12.9; >= 4.13.0, < 4.13.9; >= 4.14.0, < 4.14.4f |
| oracle | linux | 4; 5; 6 |
| qnap | qts | < 4.1.1; 4.1.1 |
| mageia | mageia | 3.0; 4.0 |
| redhat | gluster storage server for on-premise | 2.1 |
| redhat | virtualization | 3.4 |
| redhat | enterprise linux | 4.0; 5.0; 6.0; 7.0 |
| redhat | enterprise linux desktop | 5.0; 6.0; 7.0 |
| redhat | enterprise linux eus | 5.9; 6.4; 6.5; 7.3; 7.4; 7.5; 7.6; 7.7 |
| redhat | enterprise linux for ibm z systems | 5.9_s390x; 6.4_s390x; 6.5_s390x; 7.3_s390x; 7.4_s390x; 7.5_s390x; 7.6_s390x; 7.7_s390x |
| redhat | enterprise linux for power big endian | 5.0_ppc; 5.9_ppc; 6.0_ppc64; 6.4_ppc64; 7.0_ppc64 |
| redhat | enterprise linux for power big endian eus | 6.5_ppc64; 7.3_ppc64; 7.4_ppc64; 7.5_ppc64; 7.6_ppc64; 7.7_ppc64 |
| redhat | enterprise linux for scientific computing | 6.0; 7.0 |
| redhat | enterprise linux server | 5.0; 6.0; 7.0 |
| redhat | enterprise linux server aus | 5.6; 5.9; 6.2; 6.4; 6.5; 7.3; 7.4; 7.6; 7.7 |
| redhat | enterprise linux server from rhui | 5.0; 6.0; 7.0 |
| redhat | enterprise linux server tus | 6.5; 7.3; 7.6; 7.7 |
| redhat | enterprise linux workstation | 5.0; 6.0; 7.0 |
| suse | studio onsite | 1.3 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://advisories.mageia.org/MGASA-2014-0393.html(Third Party Advisory)
- http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html(Broken Link)
- http://jvn.jp/en/jp/JVN55667175/index.html(Third Party Advisory)
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000126(Third Party Advisory, VDB Entry)
- http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html(Third Party Advisory)
- http://linux.oracle.com/errata/ELSA-2014-1306.html(Third Party Advisory)
- http://linux.oracle.com/errata/ELSA-2014-3075.html(Third Party Advisory)
- http://linux.oracle.com/errata/ELSA-2014-3077.html(Third Party Advisory)
- http://linux.oracle.com/errata/ELSA-2014-3078.html(Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00038.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00041.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00042.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00048.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00023.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-updates/2014-10/msg00025.html(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=141216207813411&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141216668515282&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141235957116749&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141319209015420&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141330425327438&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141330468527613&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141345648114150&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383026420882&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383081521087&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383138121313&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383196021590&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383244821813&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383304022067&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383353622268&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141383465822787&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141450491804793&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141576728022234&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141577137423233&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141577241923505&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141577297623641&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141585637922673&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141694386919794&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=141879528318582&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=142113462216480&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=142118135300698&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=142358026505815&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=142358078406056&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=142721162228379&w=2(Mailing List)
- http://marc.info/?l=bugtraq&m=142805027510172&w=2(Mailing List)
- http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html(Exploit, Third Party Advisory, VDB Entry)
- http://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.html(Exploit, Third Party Advisory, VDB Entry)
- http://rhn.redhat.com/errata/RHSA-2014-1306.html(Third Party Advisory)
- http://rhn.redhat.com/errata/RHSA-2014-1311.html(Third Party Advisory)
- http://rhn.redhat.com/errata/RHSA-2014-1312.html(Third Party Advisory)
- http://rhn.redhat.com/errata/RHSA-2014-1354.html(Third Party Advisory)
- http://seclists.org/fulldisclosure/2014/Oct/0(Mailing List, Third Party Advisory)
- http://secunia.com/advisories/58200(Broken Link)
- http://secunia.com/advisories/59272(Broken Link)
- http://secunia.com/advisories/59737(Broken Link)
- http://secunia.com/advisories/59907(Broken Link)
- http://secunia.com/advisories/60024(Broken Link)
- http://secunia.com/advisories/60034(Broken Link)
- http://secunia.com/advisories/60044(Broken Link)
- http://secunia.com/advisories/60055(Broken Link)
- http://secunia.com/advisories/60063(Broken Link)
- http://secunia.com/advisories/60193(Broken Link)
- http://secunia.com/advisories/60325(Broken Link)
- http://secunia.com/advisories/60433(Broken Link)
- http://secunia.com/advisories/60947(Broken Link)
- http://secunia.com/advisories/61065(Broken Link)
- http://secunia.com/advisories/61128(Broken Link)
- http://secunia.com/advisories/61129(Broken Link)
- http://secunia.com/advisories/61188(Broken Link)
- http://secunia.com/advisories/61283(Broken Link)
- http://secunia.com/advisories/61287(Broken Link)
- http://secunia.com/advisories/61291(Broken Link)
- http://secunia.com/advisories/61312(Broken Link)
- http://secunia.com/advisories/61313(Broken Link)
- http://secunia.com/advisories/61328(Broken Link)
- http://secunia.com/advisories/61442(Broken Link)
- http://secunia.com/advisories/61471(Broken Link)
- http://secunia.com/advisories/61479(Broken Link)
- http://secunia.com/advisories/61485(Broken Link)
- http://secunia.com/advisories/61503(Broken Link)
- http://secunia.com/advisories/61550(Broken Link)
- http://secunia.com/advisories/61552(Broken Link)
- http://secunia.com/advisories/61565(Broken Link)
- http://secunia.com/advisories/61603(Broken Link)
- http://secunia.com/advisories/61618(Broken Link)
- http://secunia.com/advisories/61619(Broken Link)
- http://secunia.com/advisories/61622(Broken Link)
- http://secunia.com/advisories/61626(Broken Link)
- http://secunia.com/advisories/61633(Broken Link)
- http://secunia.com/advisories/61641(Broken Link)
- http://secunia.com/advisories/61643(Broken Link)
- http://secunia.com/advisories/61654(Broken Link)
- http://secunia.com/advisories/61676(Broken Link)
- http://secunia.com/advisories/61700(Broken Link)
- http://secunia.com/advisories/61703(Broken Link)
- http://secunia.com/advisories/61711(Broken Link)
- http://secunia.com/advisories/61715(Broken Link)
- http://secunia.com/advisories/61780(Broken Link)
- http://secunia.com/advisories/61816(Broken Link)
- http://secunia.com/advisories/61855(Broken Link)
- http://secunia.com/advisories/61857(Broken Link)
- http://secunia.com/advisories/61873(Broken Link)
- http://secunia.com/advisories/62228(Broken Link)
- http://secunia.com/advisories/62312(Broken Link)
- http://secunia.com/advisories/62343(Broken Link)
- http://support.apple.com/kb/HT6495(Third Party Advisory)
- http://support.novell.com/security/cve/CVE-2014-7169.html(Third Party Advisory)
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash(Third Party Advisory)
- http://twitter.com/taviso/statuses/514887394294652929(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021272(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021279(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1021361(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004879(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004897(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004898(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004915(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21685541(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21685604(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21685733(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21685749(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21685914(Broken Link)
- http://www-01.ibm.com/support/docview.wss?uid=swg21686084(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21686131(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21686246(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21686445(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21686447(Broken Link)
- http://www-01.ibm.com/support/docview.wss?uid=swg21686479(Broken Link)
- http://www-01.ibm.com/support/docview.wss?uid=swg21686494(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21687079(Third Party Advisory)
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096315(Broken Link)
- http://www.debian.org/security/2014/dsa-3035(Mailing List, Third Party Advisory)
- http://www.kb.cert.org/vuls/id/252743(Third Party Advisory, US Government Resource)
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:164(Broken Link)
- http://www.novell.com/support/kb/doc.php?id=7015701(Third Party Advisory)
- http://www.novell.com/support/kb/doc.php?id=7015721(Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2014/09/24/32(Mailing List)
- http://www.oracle.com/technetwork/topics/security/bashcve-2014-7169-2317675.html(Patch, Third Party Advisory)
- http://www.qnap.com/i/en/support/con_show.php?cid=61(Third Party Advisory)
- http://www.securityfocus.com/archive/1/533593/100/0/threaded(Broken Link, Third Party Advisory, VDB Entry)
- http://www.ubuntu.com/usn/USN-2363-1(Third Party Advisory)
- http://www.ubuntu.com/usn/USN-2363-2(Third Party Advisory)
- http://www.us-cert.gov/ncas/alerts/TA14-268A(Third Party Advisory, US Government Resource)
- http://www.vmware.com/security/advisories/VMSA-2014-0010.html(Third Party Advisory)
- https://access.redhat.com/articles/1200223(Third Party Advisory)
- https://access.redhat.com/node/1200223(Third Party Advisory)
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes(Broken Link)
- https://kb.bluecoat.com/index?page=content&id=SA82(Broken Link)
- https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648(Third Party Advisory)
- https://kc.mcafee.com/corporate/index?page=content&id=SB10085(Broken Link)
- https://support.apple.com/kb/HT6535(Third Party Advisory)
- https://support.citrix.com/article/CTX200217(Third Party Advisory)
- https://support.citrix.com/article/CTX200223(Permissions Required)
- https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15629.html(Third Party Advisory)
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04497075(Broken Link)
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c04518183(Broken Link)
- https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102673&src=securityAlerts(Third Party Advisory)
- https://www.arista.com/en/support/advisories-notices/security-advisories/1008-security-advisory-0006(Third Party Advisory)
- https://www.exploit-db.com/exploits/34879/(Exploit, Third Party Advisory, VDB Entry)
- https://www.suse.com/support/shellshock/(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-7169(US Government Resource)
Weakness Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
OS Command Injection vulnerabilities allow attackers to execute arbitrary operating system commands by injecting malicious input into shell command construction. This weakness class targets system shells like Bash, cmd.exe, and PowerShell, where metacharacters such as semicolons, pipes, backticks, and command substitution operators can alter the intended command structure. The consequences of successful OS command injection range from data theft and system modification to complete infrastructure compromise.
CVE-2014-7169 specifically addresses a bypass of the initial Shellshock fix (CVE-2014-6271). While the first patch attempted to restrict the execution of trailing commands after function definitions in environment variables, it did not completely eliminate the parsing vulnerability. Researchers discovered that by using different syntax patterns, such as redirecting output with > or using parser state confusion techniques, the patch could be circumvented. The vulnerability demonstrates a common challenge in security patching: the initial fix addressed the specific exploitation technique rather than the root cause, leaving the fundamental parser flaw exploitable through alternative methods. This is why CVE-2014-7169 was assigned as a separate CVE and required a second, more comprehensive patch. Learn more about OS Command Injection (CWE-78)
Impact Analysis
CVE-2014-7169 carries a CVSS 3.1 base score of 9.8 (CRITICAL), identical to the original Shellshock vulnerability it bypasses.
Confidentiality (High): Like CVE-2014-6271, successful exploitation allows arbitrary command execution with the privileges of the targeted process. This provides full access to all data accessible by the service account, including web application source code, database credentials, API keys, cryptographic material, and user data. Systems patched only for CVE-2014-6271 but not CVE-2014-7169 remained fully vulnerable to data exfiltration through this bypass.
Integrity (High): Command execution enables the attacker to modify files, install persistent backdoors, alter system configurations, deploy malware, and manipulate application logic. The bypass nature of this vulnerability means that organizations that believed they had remediated Shellshock by applying only the first patch were still exposed to all the same integrity impacts.
Availability (High): Attackers can terminate processes, consume resources, encrypt or delete data, and render systems inoperable. The continued vulnerability of systems that applied only the initial patch extended the window of exploitation for Shellshock-based campaigns, resulting in additional compromises during the period between the two patches.
Scope (Unchanged): The scope remains technically unchanged but practically extends to the entire server environment when web-facing services are compromised. The EPSS score of 0.90108 (99.59th percentile) confirms that this bypass variant is also heavily exploited, particularly against systems where administrators applied only the first Shellshock patch.
Exploit Maturity
Active Exploitation: CVE-2014-7169 has been actively exploited in the wild, particularly in the critical period between the release of the initial Shellshock patch and the more comprehensive fix. CISA added it to the KEV catalog on January 28, 2022, confirming continued exploitation. Threat actors adapted their Shellshock exploits to use the bypass techniques almost immediately after the first patch was released.
Ransomware Association: The CISA KEV catalog does not directly associate CVE-2014-7169 with ransomware campaigns. However, as a command execution vulnerability with identical impact to CVE-2014-6271, it is equally suitable for initial access in ransomware attack chains.
Public Exploits: Multiple public exploits are available, including exploit code on Packet Storm Security and the CA Technologies GNU Bash Shellshock exploit. Oracle published a specific advisory addressing this variant in their products.
EPSS Context: The EPSS score of 0.90108 (99.59th percentile) places this in the top 0.5% of all CVEs for exploitation probability. While slightly lower than CVE-2014-6271's EPSS score, it remains extraordinarily high, reflecting the ongoing exploitation of systems with incomplete Shellshock patches.
KEV Deadline: The CISA remediation deadline was July 28, 2022. Organizations must ensure they have applied patches that address both CVE-2014-6271 and CVE-2014-7169 to be fully protected against Shellshock.
Remediation
-
Verify that Bash patches cover both CVE-2014-6271 and CVE-2014-7169. The initial Bash patch for Shellshock was incomplete. Ensure your systems have the comprehensive patch that addresses CVE-2014-7169 and all subsequent Shellshock variants (CVE-2014-7186, CVE-2014-7187, CVE-2014-6277, CVE-2014-6278). Verify by running the test case:
env X='() { (a)=>' bash -c "echo date"; cat echoshould not create a file named "echo" on patched systems. -
Apply vendor-specific patches comprehensively. Each distribution released multiple rounds of Bash updates to address Shellshock variants. On Red Hat/CentOS, Debian/Ubuntu, SUSE, and other distributions, ensure you have the latest Bash package that includes all Shellshock fixes. Check vendor advisories for specific package version requirements.
-
Audit all systems for incomplete patching. Organizations that applied the first Shellshock patch but not the subsequent updates may have a false sense of security. Run automated vulnerability scans to identify any Bash instances still vulnerable to CVE-2014-7169, including on embedded systems, containers, and virtual machine templates.
-
Re-scan all systems that were considered patched. After CVE-2014-6271 was patched, many organizations marked Shellshock as remediated. CVE-2014-7169 proved that incomplete patching left systems vulnerable. Re-validate all previously "patched" systems to confirm they are protected against this bypass variant.
-
Implement defense-in-depth measures. Deploy WAF rules that detect both the original Shellshock pattern and bypass variants. Monitor network traffic for exploitation attempts using updated IDS/IPS signatures that cover CVE-2014-7169-specific payloads.
-
Discontinue use of Bash in web-facing services where possible. Replace CGI scripts with modern web application frameworks. Where shell scripts are necessary, use alternatives to Bash (dash, ash) that are not affected by Shellshock variants. Apply the principle of least privilege to all service accounts.
Technical Details
CVE-2014-7169 exists because the initial fix for CVE-2014-6271 addressed the specific exploitation technique (trailing commands after function definitions) but did not fully resolve the underlying parser flaw in Bash's environment variable processing. Security researcher Tavis Ormandy demonstrated that the patch could be bypassed using alternative syntax that exploited remaining parser state issues.
The canonical test for this vulnerability uses: env X='() { (a)=>' bash -c "echo date". On vulnerable systems, this creates a file named "echo" containing the output of the date command, demonstrating that the parser still allows unintended code execution through environment variables. The bypass works by exploiting how the parser handles syntax errors within function definitions, causing it to enter a confused state where subsequent command elements are executed.
The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) is identical to CVE-2014-6271 because the exploitation prerequisites and impact are the same. The attack is network-based, requires no authentication, and achieves full command execution. The only difference is the specific payload syntax used to trigger the vulnerability.
The root cause, like CVE-2014-6271, lies in the parse_and_execute() function in variables.c. The initial patch attempted to add bounds checking to prevent execution of trailing commands, but the parser's handling of error conditions and certain syntactic constructs still allowed code execution through different code paths. The final comprehensive fix required a more fundamental restructuring of how Bash processes function definitions from environment variables, limiting the parser to only accept function definition syntax and rejecting all other constructs.
Frequently Asked Questions
What is CVE-2014-7169?
CVE-2014-7169 is a critical command injection vulnerability in GNU Bash through version 4.3 that bypasses the initial patch for the Shellshock vulnerability (CVE-2014-6271). While the first Shellshock fix prevented the original exploitation technique, CVE-2014-7169 demonstrates that alternative syntax patterns could still achieve arbitrary command execution through environment variables, requiring a second, more comprehensive patch.
How is CVE-2014-7169 different from CVE-2014-6271?
Both vulnerabilities exploit the same fundamental flaw in Bash's environment variable function import mechanism. CVE-2014-6271 was the original Shellshock vulnerability, and the first patch attempted to fix it. CVE-2014-7169 was discovered when researchers found that the initial patch was incomplete and could be bypassed using different syntax patterns. The impact is identical: unauthenticated remote command execution on any system where Bash processes environment variables from untrusted sources.
How do I fix CVE-2014-7169?
Ensure your Bash installation includes patches for both CVE-2014-6271 and CVE-2014-7169 (and ideally all subsequent Shellshock variants). Systems that only received the first Shellshock patch remain vulnerable. Update Bash through your distribution's package manager and verify the fix by running the test case. Re-scan all systems that were previously marked as patched for Shellshock.
How severe is CVE-2014-7169?
CVE-2014-7169 is rated CRITICAL with a CVSS 3.1 score of 9.8, identical to the original Shellshock. Its EPSS score of 0.90108 (99.59th percentile) confirms extremely high exploitation probability. The bypass nature of this vulnerability means that many organizations that believed they had addressed Shellshock remained vulnerable until they applied the comprehensive second patch. CISA includes it in the Known Exploited Vulnerabilities catalog alongside CVE-2014-6271.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.