CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Jul 28, 2022
Description
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
EPSS — Exploit Probability
90.1%
Higher than 99.6% of all CVEs
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2014-7169
Risk Assessment
HIGHIn CISA KEV
High EPSS
Details
- Severity
- High
- EPSS
- 90.1%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 0
Timeline
Published
Jan 28, 2022
Added to KEV
Jan 28, 2022
Remediation Due
Jul 28, 2022