Command injection in Bash - CVE-2014-6278
Published: January 24, 2017 / Updated: October 2, 2025
Vulnerability details
The weakness exists due to an incomplete fix related to the parsing of user scripts. By using attack vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, a remote attacker can execute arbitrary code with privileges of the current user. The vulnerability was introduced by incorrect patching of vulnerabilities #1 (CVE-2014-6271), #2 (CVE-2014-7169) and #3 (CVE-2014-6277)
Successful exploitation results in arbitrary code execution on the vulnerable system.
Note: this vulnerability was being actively exploited.
Affected software
ProtecTIER Entry Edition (PID 5639-PTC) - TS7610 / TS7620
ProtecTIER Appliance Edition (PID 5639-PTB) - TS7650AP1
ProtecTIER Enterprise Edition (PID 5639-PTA) - TS7650G
IBM BladeCenter Advanced Management Module
Gentoo Linux
Ubuntu
StoreAll OS
StoreEver ESL G3 Tape Library
Automation Insight
Virtualization Performance Viewer
TippingPoint Next Generation Firewall
Operations Analytics
HP Business Service Automation Essentials
Operations Agent Virtual Appliance
FlashSystem V840 9846-AE1 & 9848-AE1
FlashSystem 840 9840-AE1 & 9843-AE1
Hyper-Scale Manager
Integrity SD2 CB900s i4 & i2
NonStop Virtual TapeServer (VTS)
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1
bash (Alpine package)
FOS Firmware
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V7000
IBM Storwize V5000
How to mitigate CVE-2014-6278
bash (Alpine package) - update to 4.3.30-r0
IBM BladeCenter Advanced Management Module - update to BPET68C-3.68C
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.2.7
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.7
Hyper-Scale Manager - update to 1.5.0.59
Integrity SD2 CB900s i4 & i2 - update to 3.8.0
FOS Firmware - addressed in versions 6.2.2f9, 6.4.2a3, 6.4.3f3, 7.0.0d1, 7.0.2e1, 7.1.0cb, 7.1.1c1, 7.1.2b1, 7.2.0d6, 7.2.1c1
StoreAll OS - addressed in versions 6.3.4, 6.5.5
NonStop Virtual TapeServer (VTS) - addressed in versions 6.04.05, 8.3, 8.4
IBM Storwize V3500 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
IBM Storwize V3700 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
IBM Storwize V7000 - addressed in versions 7.1.0.11, 7.2.0.9
IBM Storwize V5000 - addressed in versions 7.1.0.11, 7.2.0.9, 7.3.0.7
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1 - update to 7.3.0.7
Links to Public Exploits and PoC-codes
- Exploit #39 - Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner (March 18, 2020)
- Exploit #896 - Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Exploit (Shellshock) (March 18, 2020)
- Exploit #897 - Cisco UCS Manager 2.1(1b) - Remote Exploit (Shellshock) (March 18, 2020)
- Exploit #898 - dhclient 4.1 - Bash Environment Variable Command Injection (PoC) (Shellshock) (March 18, 2020)
- Exploit #899 - Apache mod_cgi - Remote Exploit (Shellshock) (March 18, 2020)
- Exploit #900 - GNU bash 4.3.11 - Environment Variable dhclient Exploit (March 18, 2020)
- Exploit #1776 - CUPS Filter Bash Environment Variable Code Injection (Shellshock) (March 18, 2020)
- Exploit #1780 - Apache mod_cgi Bash Environment Variable Code Injection (Shellshock) (March 18, 2020)
External References
Related Security Bulletins
- Multiple RCE vulnerabilities in GNU Bash aka Shellshock
- Ubuntu update for Bash
- Gentoo update for Bash
- SUSE Linux update for Containment-Studio
- openSUSE update for Shellshock
- Command injection in bash (Alpine package)
- Multiple vulnerabilities in IBM FlashSystem 840 and V840
- Multiple vulnerabilities in IBM FOS Firmware
- Multiple vulnerabilities in HP Automation Insight
- Multiple vulnerabilities in HP Business Service Automation Essentials
- Multiple vulnerabilities in HP Operations Analytics
- Multiple vulnerabilities in HP Next Generation Firewall (NGFW)
- Multiple vulnerabilities in HP Integrity SD2 CB900s i4 & i2
- Multiple vulnerabilities in HP Operation Agent Virtual Appliance
- Multiple vulnerabilities in HP Virtualization Performance Viewer
- Multiple vulnerabilities in HP NonStop Virtual TapeServer (VTS)
- Multiple vulnerabilities in HP StoreEver ESL G3 Tape Library
- Multiple vulnerabilities in HP StoreAll Operating System
- Multiple vulnerabilities in SAN Volume Controller and Storwize Family
- Multiple vulnerabilities in IBM ProtecTIER
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module (AMM)
- Multiple vulnerabilities in IBM Hyper-Scale Manager