CVE-2014-7169
Exploited in the wild. In CISA KEV since 2022‑01‑28. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check which Bash version your systems run (for example, run:
bash --version) and identify whether you’re on an affected version. - If you run an affected vendor/platform, upgrade to the fixed version listed for your platform: Alt Linux SPT → update per vendor instructions; EOS → 4.9.12; QTS → 1.1.1.
- If you can’t upgrade immediately, reduce exposure by removing or restricting remote features that pass crafted environment variables across a privilege boundary (for example, avoid allowing remote forced command setups that run under different privileges).
- After updating, verify Bash is the updated fixed version and review logs for suspicious file-write or execution attempts around remote access services.
What it is
From the CVE record
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
In plain language
Written by AI from the recordCVE-2014-7169 is a very serious Bash bug that lets an attacker misuse specially crafted environment settings to write files or cause severe system damage; if you run affected Bash versions on a server, you should act now.
CVE-2014-7169 is a Bash environment-handling flaw (CWE-78) where malformed function definitions in environment variables can cause Bash to process unintended trailing strings, enabling remote attackers to write files or otherwise impact the system; it was added to CISA KEV with a required patch deadline.
If you're affected
- Remote file write on servers
- Full system compromise risk
- Service outage and downtime
- Ransomware path via takeover
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2022-01-28.
US federal agencies must remediate by 2022-07-28.
Apply updates per vendor instructions.
- Public exploits
3 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
100% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
A public exploit existed 47 days before the patch.
- OpenVAS check added
- EPSS band changehigh → critical
- EPSS band changecritical → high
- Patch availablerecord updated
- Public exploit / PoCsource: packetstorm
- Added to CISA KEV
Affected products
- infosphere guardium database activity monitoringSecurity Products / vuln-mgmt-scanner
- pureapplication systemCloud & SaaS / cloud-platform
- qradar risk managerSecurity Products / vuln-mgmt-scanner
- qradar security information and event managerSecurity Products / siem-soar
- qradar vulnerability managerSecurity Products / vuln-mgmt-scanner
- smartcloud entry applianceCloud & SaaS / saas-application
- smartcloud provisioningCloud & SaaS / cloud-platform
- software defined network for virtual environmentsNetworking Infrastructure / network-management
- big-ip access policy managerNetworking Infrastructure / firewall
- big-ip advanced firewall managerNetworking Infrastructure / firewall
- big-ip analyticsNetworking Infrastructure / network-management
- big-ip application acceleration managerNetworking Infrastructure / load-balancer-proxy
- big-ip application security managerNetworking Infrastructure / firewall
- big-ip edge gatewayNetworking Infrastructure / vpn-gateway
- big-ip global traffic managerNetworking Infrastructure / load-balancer-proxy
- big-ip link controllerNetworking Infrastructure / router-switch
- gluster storage server for on-premiseOperating Systems / linux-distro
- virtualizationOperating Systems / linux-distro
- enterprise linux workstationOperating Systems / linux-distro
- enterprise linux for ibm z systemsOperating Systems / linux-distro
- enterprise linux for power big endianOperating Systems / linux-distro
- enterprise linux for power big endian eusOperating Systems / linux-distro
- enterprise linux for scientific computingOperating Systems / linux-distro
- enterprise linux server from rhuiOperating Systems / linux-distro
And 44 more affected products. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored 9.8 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- altlinux.ru/news/archive/2015/03/item/735/
- packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.html
- www-01.ibm.com/support/docview.wss?uid=ssg1S1004897
And 159 more references. See all after sign-in
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Ibm, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI