CISA KEV · catalog date Jan 28, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a…
Exploited in the wild (CISA KEV since Jan 28, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Jul 26, 2026.
As of Aug 27, 2026
Normalized restatement
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
- State
- PUBLISHED
- Published
- Sep 24, 2014
- Updated
- Oct 22, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAdebianOriginal evidence ↗
Record text: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Inspect raw assertion
- Field
container- Value
- GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999930000000
FIRST EPSS · score date Jul 26, 2026 · 100th percentile · first observed Jul 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Inspect raw assertion
- Field
container- Value
- GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
100% probability · 99.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999990000000; percentile 0.999930000000
Applicability
Cited product scope
Grouped from 37 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
86 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-94613e1f5039e71a9805f20421d56ac6a61e2707d3f97a08fdf6823a65dc7b76Linked exactInspect raw assertion
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 24 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 10.0.0; through excluding 10.10.0
- Match ID
864b5480-704f-4636-a938-7d95ad4223ad
product-4a9e5f8d20063f77280080e593816b0a266f41ffdabcb0171c11eeb4f7f06280Linked exactInspect raw assertions
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 4.14.0; through excluding 4.14.4f
- Match ID
816a16af-1f5e-483a-aa89-3022818fae43
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 4.13.0; through excluding 4.13.9
- Match ID
8296875a-64fa-4592-848a-a923126bd8af
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.9.0; through excluding 4.9.12
- Match ID
dca5a28d-79b6-4f3e-9c98-65d4dfad8ee7
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 4.10.0; through excluding 4.10.9
- Match ID
9b1dc7ef-c994-4252-9dfe-dca63fb17ae0
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 4.11.0; through excluding 4.11.11
- Match ID
9056776f-03f6-4c3d-8635-37d66fd16eaa
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 4.12.0; through excluding 4.12.9
- Match ID
afee6963-f73f-4b71-b4f8-6e550fbda5f6
product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
01eda41c-6b2e-49af-b503-eb3882265c11
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
815d70a8-47d3-459c-a32c-9feaca0659d1
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb66db75-2b16-4ebf-9b93-ce49d8086e41
product-661ba239878ea580d6e32ca8ae247564c7b76bd289a2733bb7ecf16b436530a4Linked exactInspect raw assertion
cpe:2.3:a:checkpoint:security_gateway:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 20 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding r77.30
- Match ID
2853a787-e5f1-4455-9482-7c538b80556c
product-59483e588bd7cffee98740b5779bff6b94fe418159a67cfafaf4b1731412c93cLinked exactInspect raw assertion
cpe:2.3:h:citrix:netscaler_sdx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 23 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8968e39a-1e16-4b7f-a16a-190ebc20d04f
product-fc5b3b42d58a21ab44a53d3b2723155a9c4d248a0a24dbb503c4f9f64eab452fLinked exactInspect raw assertions
cpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 23 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 10.5; through excluding 10.5.52.11r1
- Match ID
bae3cc45-49e5-40de-b5c3-52a754a9c599
cpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 23 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 10; through excluding 10.1.129.11r1
- Match ID
665ef643-3cdc-4518-9693-0d49f0870283
cpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 23 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 9.3.67.5r1
- Match ID
ff1db4b7-afcc-4d56-95ba-c66ab7a36680
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f59a04-14cf-49e2-9973-645477ea09da
product-9b552796b654942d1cd0b56c29df5fdc7d2dada9b336a77dfed14d54865dca97Linked exactInspect raw assertion
cpe:2.3:h:f5:arx:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 22 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c6ac80f-9d91-468d-bee3-6a0759723673
product-26bd21a02cd149e0c42e4fcea379e43a36df524ae5cbed6b9aa5bedf4b0cb9e2Linked exactInspect raw assertion
cpe:2.3:o:f5:arx_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 22 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 6.0.0; through including 6.4.0
- Match ID
48a2fba9-207f-4f16-932d-bf0ba3440503
product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cfa77c6b-72db-4d57-87cf-11f2c7edb828
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.5.1
- Match ID
8e910d60-1145-4229-9890-80d2d67c3845
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 10.1.0; through including 10.2.4
- Match ID
79618ab4-7a8e-4488-8608-57ec2f8681fe
product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b276e4df-69fc-4158-b93a-781a45605034
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 11.3.0; through including 11.5.1
- Match ID
48bbef73-e87d-467f-85eb-47be212df0e8
product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_analytics:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b70d2bd5-8e3f-4b57-84ef-3af40f6378f1
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.5.1
- Match ID
ee23220d-e364-41b7-a440-43b3aa4a716a
product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 11.4.0; through including 11.5.1
- Match ID
c483253f-841e-4d4e-9b4a-932e9d07268b
cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e5b40837-ec2b-41fb-acc3-806054eaf28c
product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
475f0ef8-42cb-4099-9c4a-390f946c4924
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 9
- Logic
- OR
- Version bounds
- from including 10.0.0; through including 10.2.4
- Match ID
667d3780-3949-41ac-83de-5bcb8b36c382
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 10
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.5.1
- Match ID
4f0e7766-bdb4-42ab-b6cc-6b4e86a10038
product-2ef3e3330ef867854f3e55800c0e0cdd023371aa73dd9e7add7dfa128e66c26aLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 12
- Logic
- OR
- Version bounds
- from including 10.1.0; through including 10.2.4
- Match ID
a8347412-dc42-4b86-bf6e-a44a5e1541ed
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 13
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.3.0
- Match ID
c8942d9d-8e3a-4876-8e93-ed8d201ff546
product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d7d7863d-b064-4d7a-a66b-c3d3523425fd
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 15
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.5.1
- Match ID
06ba93c0-a7ae-4a8e-bd74-08149a204463
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 14
- Logic
- OR
- Version bounds
- from including 10.0.0; through including 10.2.4
- Match ID
7b5af8c8-578e-4fd7-8baa-53a57ee4c653
product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 17
- Logic
- OR
- Version bounds
- from including 10.0.0; through including 10.2.4
- Match ID
1df6bb8a-fa63-4dbc-891c-256ff23cbcf0
cpe:2.3:a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5cdec701-dab3-4d92-aa67-b886e6693e46
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 18
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.5.1
- Match ID
3e0d8f52-0ead-4e02-a8d8-cbae2cdc703b
product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2ff5a5f6-4ba3-4276-8679-b5560eacf2e0
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 20
- Logic
- OR
- Version bounds
- from including 10.0.0; through including 10.2.4
- Match ID
289ceabb-22a2-436d-ae4b-4bda2d0eafdb
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 21
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.5.1
- Match ID
c6d61bf2-69d8-4ad2-85cd-d87f640a6888
product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 23
- Logic
- OR
- Version bounds
- from including 11.3.0; through including 11.5.1
- Match ID
e9a06d61-e6cb-4a8a-b06d-9fea1812c167
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb8d3b87-b8f5-490a-b1d9-04f2ee93eea3
product-c292d03866ff8f16359315a2e8a89dcc4f7e5d70bc08cbce1625d4ee2032777aLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 25
- Logic
- OR
- Version bounds
- from including 10.0.0; through including 10.2.4
- Match ID
2c0b4c01-c71e-4e35-b63a-68395984e033
cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 26
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.4.1
- Match ID
9828cba5-bb72-46e2-987d-633a5b3e2aff
product-da9ac0561bce1fb3f2be50345c74276dffd0904067ef9858397b76a9fb869f4cLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 28
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.3.0
- Match ID
68bc025a-d45e-45fb-a4e4-1c89320b5bbe
cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 27
- Logic
- OR
- Version bounds
- from including 10.0.0; through including 10.2.4
- Match ID
bb60c39d-52ed-47dd-9fb9-2b4bc8d9f8ac
product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47bLinked exactInspect raw assertions
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 30
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.3.0
- Match ID
7c75978b-566b-4353-8716-099cb8790ee0
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 29
- Logic
- OR
- Version bounds
- from including 10.0.0; through including 10.2.4
- Match ID
ae007a64-5867-4b1a-aefb-3ab2cd6a5ea4
product-b8aa0349e7204b53f4ad3e4f173c83d7535e55b4e37cfc14d47a2aed72c1a867Linked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_cloud:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 31
- Logic
- OR
- Version bounds
- from including 4.0.0; through including 4.4.0
- Match ID
bc24b891-6dba-4c02-b4cf-8d1ca53b4b74
product-64a87e2f5b8db7cf37895c491723c860754a6486575c5ac3cbbe3d7cf58a3478Linked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_device:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 21 · node/0 · match 32
- Logic
- OR
- Version bounds
- from including 4.2.0; through including 4.4.0
- Match ID
0bb0fdac-c49d-4e63-aca9-7bad7c93a5d2
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.