Evidence dossier

CVE-2014-6271

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a…

Exploited in the wild (CISA KEV since Jan 28, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Jul 26, 2026.

98.698.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

State
PUBLISHED
Published
Sep 24, 2014
Updated
Oct 22, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    debian

    Record text: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

    Inspect raw assertion
    Field
    container
    Value
    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 100% probability · 99.99th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999990000000; percentile 0.999930000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jan 28, 2022 · first observed Jul 19, 2026

Exploit likelihood100.00%

FIRST EPSS · score date Jul 26, 2026 · 100th percentile · first observed Jul 27, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
debianOriginal assertion
Record text

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

Inspect raw assertion
Field
container
Value
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

100% probability · 99.99th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999990000000; percentile 0.999930000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
345Underlying assertions
85Canonical products
334Target assertions
11Constraint assertions

Grouped from 37 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

86 scope groups

debian · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · OPERATING SYSTEMapplemac_os_xVulnerable target · 1 assertions
Any version (unconstrained) (>= 10.0.0, < 10.10.0)Canonical identity product-94613e1f5039e71a9805f20421d56ac6a61e2707d3f97a08fdf6823a65dc7b76Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    24 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 10.0.0; through excluding 10.10.0
    Match ID
    864b5480-704f-4636-a938-7d95ad4223ad
NVD CPE · OPERATING SYSTEMaristaeosVulnerable target · 6 assertions
Any version (unconstrained) (>= 4.10.0, < 4.10.9); Any version (unconstrained) (>= 4.11.0, < 4.11.11); Any version (unconstrained) (>= 4.12.0, < 4.12.9); Any version (unconstrained) (>= 4.13.0, < 4.13.9); Any version (unconstrained) (>= 4.14.0, < 4.14.4f); Any version (unconstrained) (>= 4.9.0, < 4.9.12)Canonical identity product-4a9e5f8d20063f77280080e593816b0a266f41ffdabcb0171c11eeb4f7f06280Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 4.14.0; through excluding 4.14.4f
    Match ID
    816a16af-1f5e-483a-aa89-3022818fae43
  2. cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 4.13.0; through excluding 4.13.9
    Match ID
    8296875a-64fa-4592-848a-a923126bd8af
  3. cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 4.9.0; through excluding 4.9.12
    Match ID
    dca5a28d-79b6-4f3e-9c98-65d4dfad8ee7
  4. cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 4.10.0; through excluding 4.10.9
    Match ID
    9b1dc7ef-c994-4252-9dfe-dca63fb17ae0
  5. cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 4.11.0; through excluding 4.11.11
    Match ID
    9056776f-03f6-4c3d-8635-37d66fd16eaa
  6. cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 4.12.0; through excluding 4.12.9
    Match ID
    afee6963-f73f-4b71-b4f8-6e550fbda5f6
NVD CPE · OPERATING SYSTEMcanonicalubuntu_linuxVulnerable target · 3 assertions
Version 10.04; Version 12.04; Version 14.04Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    01eda41c-6b2e-49af-b503-eb3882265c11
  2. cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    815d70a8-47d3-459c-a32c-9feaca0659d1
  3. cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    18 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb66db75-2b16-4ebf-9b93-ce49d8086e41
NVD CPE · APPLICATIONcheckpointsecurity_gatewayVulnerable target · 1 assertions
Any version (unconstrained) (< r77.30)Canonical identity product-661ba239878ea580d6e32ca8ae247564c7b76bd289a2733bb7ecf16b436530a4Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:checkpoint:security_gateway:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    20 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding r77.30
    Match ID
    2853a787-e5f1-4455-9482-7c538b80556c
NVD CPE · HARDWAREcitrixnetscaler_sdxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-59483e588bd7cffee98740b5779bff6b94fe418159a67cfafaf4b1731412c93cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:citrix:netscaler_sdx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    23 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8968e39a-1e16-4b7f-a16a-190ebc20d04f
NVD CPE · OPERATING SYSTEMcitrixnetscaler_sdx_firmwareVulnerable target · 3 assertions
Any version (unconstrained) (>= 10, < 10.1.129.11r1); Any version (unconstrained) (>= 10.5, < 10.5.52.11r1); Any version (unconstrained) (< 9.3.67.5r1)Canonical identity product-fc5b3b42d58a21ab44a53d3b2723155a9c4d248a0a24dbb503c4f9f64eab452fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    23 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 10.5; through excluding 10.5.52.11r1
    Match ID
    bae3cc45-49e5-40de-b5c3-52a754a9c599
  2. cpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    23 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 10; through excluding 10.1.129.11r1
    Match ID
    665ef643-3cdc-4518-9693-0d49f0870283
  3. cpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    23 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 9.3.67.5r1
    Match ID
    ff1db4b7-afcc-4d56-95ba-c66ab7a36680
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 1 assertions
Version 7.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16f59a04-14cf-49e2-9973-645477ea09da
NVD CPE · HARDWAREf5arxEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-9b552796b654942d1cd0b56c29df5fdc7d2dada9b336a77dfed14d54865dca97Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:f5:arx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    22 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4c6ac80f-9d91-468d-bee3-6a0759723673
NVD CPE · OPERATING SYSTEMf5arx_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (>= 6.0.0, <= 6.4.0)Canonical identity product-26bd21a02cd149e0c42e4fcea379e43a36df524ae5cbed6b9aa5bedf4b0cb9e2Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:f5:arx_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    22 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 6.0.0; through including 6.4.0
    Match ID
    48a2fba9-207f-4f16-932d-bf0ba3440503
NVD CPE · APPLICATIONf5big-ip_access_policy_managerVulnerable target · 3 assertions
Any version (unconstrained) (>= 10.1.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.5.1); Version 11.6.0Canonical identity product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cfa77c6b-72db-4d57-87cf-11f2c7edb828
  2. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.5.1
    Match ID
    8e910d60-1145-4229-9890-80d2d67c3845
  3. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 10.1.0; through including 10.2.4
    Match ID
    79618ab4-7a8e-4488-8608-57ec2f8681fe
NVD CPE · APPLICATIONf5big-ip_advanced_firewall_managerVulnerable target · 2 assertions
Any version (unconstrained) (>= 11.3.0, <= 11.5.1); Version 11.6.0Canonical identity product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b276e4df-69fc-4158-b93a-781a45605034
  2. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 11.3.0; through including 11.5.1
    Match ID
    48bbef73-e87d-467f-85eb-47be212df0e8
NVD CPE · APPLICATIONf5big-ip_analyticsVulnerable target · 2 assertions
Any version (unconstrained) (>= 11.0.0, <= 11.5.1); Version 11.6.0Canonical identity product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_analytics:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b70d2bd5-8e3f-4b57-84ef-3af40f6378f1
  2. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.5.1
    Match ID
    ee23220d-e364-41b7-a440-43b3aa4a716a
NVD CPE · APPLICATIONf5big-ip_application_acceleration_managerVulnerable target · 2 assertions
Any version (unconstrained) (>= 11.4.0, <= 11.5.1); Version 11.6.0Canonical identity product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 7
    Logic
    OR
    Version bounds
    from including 11.4.0; through including 11.5.1
    Match ID
    c483253f-841e-4d4e-9b4a-932e9d07268b
  2. cpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e5b40837-ec2b-41fb-acc3-806054eaf28c
NVD CPE · APPLICATIONf5big-ip_application_security_managerVulnerable target · 3 assertions
Any version (unconstrained) (>= 10.0.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.5.1); Version 11.6.0Canonical identity product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    475f0ef8-42cb-4099-9c4a-390f946c4924
  2. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 9
    Logic
    OR
    Version bounds
    from including 10.0.0; through including 10.2.4
    Match ID
    667d3780-3949-41ac-83de-5bcb8b36c382
  3. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 10
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.5.1
    Match ID
    4f0e7766-bdb4-42ab-b6cc-6b4e86a10038
NVD CPE · APPLICATIONf5big-ip_edge_gatewayVulnerable target · 2 assertions
Any version (unconstrained) (>= 10.1.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.3.0)Canonical identity product-2ef3e3330ef867854f3e55800c0e0cdd023371aa73dd9e7add7dfa128e66c26aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 12
    Logic
    OR
    Version bounds
    from including 10.1.0; through including 10.2.4
    Match ID
    a8347412-dc42-4b86-bf6e-a44a5e1541ed
  2. cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 13
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.3.0
    Match ID
    c8942d9d-8e3a-4876-8e93-ed8d201ff546
NVD CPE · APPLICATIONf5big-ip_global_traffic_managerVulnerable target · 3 assertions
Any version (unconstrained) (>= 10.0.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.5.1); Version 11.6.0Canonical identity product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7d7863d-b064-4d7a-a66b-c3d3523425fd
  2. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 15
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.5.1
    Match ID
    06ba93c0-a7ae-4a8e-bd74-08149a204463
  3. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 14
    Logic
    OR
    Version bounds
    from including 10.0.0; through including 10.2.4
    Match ID
    7b5af8c8-578e-4fd7-8baa-53a57ee4c653
NVD CPE · APPLICATIONf5big-ip_link_controllerVulnerable target · 3 assertions
Any version (unconstrained) (>= 10.0.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.5.1); Version 11.6.0Canonical identity product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 17
    Logic
    OR
    Version bounds
    from including 10.0.0; through including 10.2.4
    Match ID
    1df6bb8a-fa63-4dbc-891c-256ff23cbcf0
  2. cpe:2.3:a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5cdec701-dab3-4d92-aa67-b886e6693e46
  3. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 18
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.5.1
    Match ID
    3e0d8f52-0ead-4e02-a8d8-cbae2cdc703b
NVD CPE · APPLICATIONf5big-ip_local_traffic_managerVulnerable target · 3 assertions
Any version (unconstrained) (>= 10.0.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.5.1); Version 11.6.0Canonical identity product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2ff5a5f6-4ba3-4276-8679-b5560eacf2e0
  2. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 20
    Logic
    OR
    Version bounds
    from including 10.0.0; through including 10.2.4
    Match ID
    289ceabb-22a2-436d-ae4b-4bda2d0eafdb
  3. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 21
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.5.1
    Match ID
    c6d61bf2-69d8-4ad2-85cd-d87f640a6888
NVD CPE · APPLICATIONf5big-ip_policy_enforcement_managerVulnerable target · 2 assertions
Any version (unconstrained) (>= 11.3.0, <= 11.5.1); Version 11.6.0Canonical identity product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 23
    Logic
    OR
    Version bounds
    from including 11.3.0; through including 11.5.1
    Match ID
    e9a06d61-e6cb-4a8a-b06d-9fea1812c167
  2. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb8d3b87-b8f5-490a-b1d9-04f2ee93eea3
NVD CPE · APPLICATIONf5big-ip_protocol_security_moduleVulnerable target · 2 assertions
Any version (unconstrained) (>= 10.0.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.4.1)Canonical identity product-c292d03866ff8f16359315a2e8a89dcc4f7e5d70bc08cbce1625d4ee2032777aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 25
    Logic
    OR
    Version bounds
    from including 10.0.0; through including 10.2.4
    Match ID
    2c0b4c01-c71e-4e35-b63a-68395984e033
  2. cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 26
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.4.1
    Match ID
    9828cba5-bb72-46e2-987d-633a5b3e2aff
NVD CPE · APPLICATIONf5big-ip_wan_optimization_managerVulnerable target · 2 assertions
Any version (unconstrained) (>= 10.0.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.3.0)Canonical identity product-da9ac0561bce1fb3f2be50345c74276dffd0904067ef9858397b76a9fb869f4cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 28
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.3.0
    Match ID
    68bc025a-d45e-45fb-a4e4-1c89320b5bbe
  2. cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 27
    Logic
    OR
    Version bounds
    from including 10.0.0; through including 10.2.4
    Match ID
    bb60c39d-52ed-47dd-9fb9-2b4bc8d9f8ac
NVD CPE · APPLICATIONf5big-ip_webacceleratorVulnerable target · 2 assertions
Any version (unconstrained) (>= 10.0.0, <= 10.2.4); Any version (unconstrained) (>= 11.0.0, <= 11.3.0)Canonical identity product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 30
    Logic
    OR
    Version bounds
    from including 11.0.0; through including 11.3.0
    Match ID
    7c75978b-566b-4353-8716-099cb8790ee0
  2. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 29
    Logic
    OR
    Version bounds
    from including 10.0.0; through including 10.2.4
    Match ID
    ae007a64-5867-4b1a-aefb-3ab2cd6a5ea4
NVD CPE · APPLICATIONf5big-iq_cloudVulnerable target · 1 assertions
Any version (unconstrained) (>= 4.0.0, <= 4.4.0)Canonical identity product-b8aa0349e7204b53f4ad3e4f173c83d7535e55b4e37cfc14d47a2aed72c1a867Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_cloud:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 31
    Logic
    OR
    Version bounds
    from including 4.0.0; through including 4.4.0
    Match ID
    bc24b891-6dba-4c02-b4cf-8d1ca53b4b74
NVD CPE · APPLICATIONf5big-iq_deviceVulnerable target · 1 assertions
Any version (unconstrained) (>= 4.2.0, <= 4.4.0)Canonical identity product-64a87e2f5b8db7cf37895c491723c860754a6486575c5ac3cbbe3d7cf58a3478Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_device:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    21 · node/0 · match 32
    Logic
    OR
    Version bounds
    from including 4.2.0; through including 4.4.0
    Match ID
    0bb0fdac-c49d-4e63-aca9-7bad7c93a5d2

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
10.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:C/I:C/A:C
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.