Description
This detection identifies exploitation attempts targeting CVE-2014-6271, which has a CRITICAL severity rating. GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which lets cyberattackers execute arbitrary code through a crafted environment. The flaw, known as ShellShock, affected vectors such as the ForceCommand feature in OpenSSH, the mod_cgi and mod_cgid modules in the Apache HTTP Server, and scripts executed by DHCP clients. The original fix missed part of the issue, and CVE-2014-7169 covers the remaining vulnerability.
Stats
- First seen
- July 2024
- Last seen
- October 2026
CVEs
Alert name variants
| Alert Name |
|---|
| Linux.Exploit.CVE-2014-6271 |
| MacOS.Exploit.CVE-2014-6271 |
| Script-BAT.Exploit.CVE-2014-6271 |
Related IPS Signatures
| Signature Name |
|---|
| OS-OTHER Bash CGI environment variable injection attempt |
