Apply updates per vendor instructions.
Evidence dossier
CVE-2014-7169
CVE-2014-7169
gen-56ccdaf9Normalized restatement
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
- State
- PUBLISHED
- Published
- Sep 25, 2014
- Updated
- Oct 22, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 100.0%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Probability 0.999400000000; percentile 0.999700000000
Applicability
Cited product scope
[{"status": "affected", "version": "n/a"}]unknowncpe:2.3:a:checkpoint:security_gateway:*:*:*:*:*:*:*:*; end excluding r77.30supportedcpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*; start including 10.1.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_access_policy_manager:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*; start including 11.3.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_advanced_firewall_manager:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_analytics:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*; start including 11.4.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_application_acceleration_manager:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*; start including 10.0.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_application_security_manager:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*; start including 10.1.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.3.0supportedcpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*; start including 10.0.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_global_traffic_manager:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*; start including 10.0.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_link_controller:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*; start including 10.0.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_local_traffic_manager:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*; start including 11.3.0; end including 11.5.1supportedcpe:2.3:a:f5:big-ip_policy_enforcement_manager:11.6.0:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*; start including 10.0.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.4.1supportedcpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*; start including 10.0.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.3.0supportedcpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*; start including 10.0.0; end including 10.2.4supportedcpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*; start including 11.0.0; end including 11.3.0supportedcpe:2.3:a:f5:big-iq_cloud:*:*:*:*:*:*:*:*; start including 4.0.0; end including 4.4.0supportedcpe:2.3:a:f5:big-iq_device:*:*:*:*:*:*:*:*; start including 4.2.0; end including 4.4.0supportedcpe:2.3:a:f5:big-iq_security:*:*:*:*:*:*:*:*; start including 4.0.0; end including 4.4.0supportedcpe:2.3:a:f5:enterprise_manager:*:*:*:*:*:*:*:*; start including 2.1.0; end including 2.3.0supportedcpe:2.3:a:f5:enterprise_manager:*:*:*:*:*:*:*:*; start including 3.0.0; end including 3.1.1supportedcpe:2.3:a:f5:traffix_signaling_delivery_controller:*:*:*:*:*:*:*:*; start including 4.0.0; end including 4.0.5supportedcpe:2.3:a:f5:traffix_signaling_delivery_controller:3.3.2:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:traffix_signaling_delivery_controller:3.4.1:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:traffix_signaling_delivery_controller:3.5.1:*:*:*:*:*:*:*supportedcpe:2.3:a:f5:traffix_signaling_delivery_controller:4.1.0:*:*:*:*:*:*:*supportedcpe:2.3:a:gnu:bash:*:*:*:*:*:*:*:*; end including 4.3supportedcpe:2.3:a:ibm:infosphere_guardium_database_activity_monitoring:8.2:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:infosphere_guardium_database_activity_monitoring:9.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:infosphere_guardium_database_activity_monitoring:9.1:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:pureapplication_system:*:*:*:*:*:*:*:*; start including 1.0.0.0; end including 1.0.0.4supportedcpe:2.3:a:ibm:pureapplication_system:*:*:*:*:*:*:*:*; start including 1.1.0.0; end including 1.1.0.4supportedcpe:2.3:a:ibm:pureapplication_system:2.0.0.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_risk_manager:7.1.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0:mr1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.0:mr2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.1:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.1:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.1:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.1:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p10:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p11:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p12:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p13:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p5:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p6:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p7:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p8:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.1.2:p9:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.0:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.1:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.2:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.3:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4:p5:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.4:p6:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5:p5:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.5:p6:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:p5:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:p6:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.6:p7:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.7:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.7:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.7:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.7:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.7:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8.15:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p10:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p11:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p12:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p13:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p14:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p15:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p16:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p5:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p6:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p7:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p8:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.8:p9:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_security_information_and_event_manager:7.2.9:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.1:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.2:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.3:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.4:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.6:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.6:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.6:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.6:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.6:p5:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.6:p6:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.6:p7:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:-:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p1:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p10:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p11:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p12:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p13:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p14:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p15:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p16:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p17:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p2:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p3:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p4:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p5:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p6:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p7:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p8:*:*:*:*:*:*supportedcpe:2.3:a:ibm:qradar_vulnerability_manager:7.2.8:p9:*:*:*:*:*:*supportedcpe:2.3:a:ibm:smartcloud_entry_appliance:2.3.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:smartcloud_entry_appliance:2.4.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:smartcloud_entry_appliance:3.1.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:smartcloud_entry_appliance:3.2.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:smartcloud_provisioning:2.1.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:software_defined_network_for_virtual_environments:*:*:*:*:kvm:*:*:*; end excluding 1.2.1supportedcpe:2.3:a:ibm:software_defined_network_for_virtual_environments:*:*:*:*:openflow:*:*:*; end excluding 1.2.1supportedcpe:2.3:a:ibm:software_defined_network_for_virtual_environments:*:*:*:*:vmware:*:*:*; end excluding 1.2.1supportedcpe:2.3:a:ibm:starter_kit_for_cloud:2.2.0:*:*:*:*:*:*:*supportedcpe:2.3:a:ibm:workload_deployer:*:*:*:*:*:*:*:*; start including 3.1.0; end including 3.1.0.7supportedcpe:2.3:a:novell:zenworks_configuration_management:10.3:*:*:*:*:*:*:*supportedcpe:2.3:a:novell:zenworks_configuration_management:11:*:*:*:*:*:*:*supportedcpe:2.3:a:novell:zenworks_configuration_management:11.1:*:*:*:*:*:*:*supportedcpe:2.3:a:novell:zenworks_configuration_management:11.2:*:*:*:*:*:*:*supportedcpe:2.3:a:novell:zenworks_configuration_management:11.3.0:*:*:*:*:*:*:*supportedcpe:2.3:a:redhat:gluster_storage_server_for_on-premise:2.1:*:*:*:*:*:*:*supportedcpe:2.3:a:redhat:virtualization:3.4:*:*:*:*:*:*:*supportedcpe:2.3:a:suse:studio_onsite:1.3:*:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.0:*:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.0:update_1:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.0:update_2:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.1:*:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.1:update_1:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.1:update_2:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.5:-:*:*:*:*:*:*supportedcpe:2.3:a:vmware:vcenter_server_appliance:5.5:update_1:*:*:*:*:*:*supportedcpe:2.3:h:citrix:netscaler_sdx:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:f5:arx:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:flex_system_v7000:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:san_volume_controller:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:stn6500:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:stn6800:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:stn7800:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:storwize_v3500:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:storwize_v3700:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:storwize_v5000:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:ibm:storwize_v7000:-:*:*:*:*:*:*:*constrainedcpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*; start including 10.0.0; end excluding 10.10.0supportedcpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*; start including 4.9.0; end excluding 4.9.12supportedcpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*; start including 4.10.0; end excluding 4.10.9supportedcpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*; start including 4.11.0; end excluding 4.11.11supportedcpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*; start including 4.12.0; end excluding 4.12.9supportedcpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*; start including 4.13.0; end excluding 4.13.9supportedcpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*; start including 4.14.0; end excluding 4.14.4fsupportedcpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*supportedcpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*supportedcpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*supportedcpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*; end excluding 9.3.67.5r1supportedcpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*; start including 10; end excluding 10.1.129.11r1supportedcpe:2.3:o:citrix:netscaler_sdx_firmware:*:*:*:*:*:*:*:*; start including 10.5; end excluding 10.5.52.11r1supportedcpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*supportedcpe:2.3:o:f5:arx_firmware:*:*:*:*:*:*:*:*; start including 6.0.0; end including 6.4.0supportedcpe:2.3:o:ibm:flex_system_v7000_firmware:*:*:*:*:*:*:*:*; start including 1.1.0.0; end excluding 7.1.0.11supportedcpe:2.3:o:ibm:flex_system_v7000_firmware:*:*:*:*:*:*:*:*; start including 7.2.0.0; end excluding 7.2.0.9supportedcpe:2.3:o:ibm:flex_system_v7000_firmware:*:*:*:*:*:*:*:*; start including 7.3.0.0; end excluding 7.3.0.7supportedcpe:2.3:o:ibm:san_volume_controller_firmware:*:*:*:*:*:*:*:*; start including 1.1.0.0; end excluding 7.1.0.11supportedcpe:2.3:o:ibm:san_volume_controller_firmware:*:*:*:*:*:*:*:*; start including 7.2.0.0; end excluding 7.2.0.9supportedcpe:2.3:o:ibm:san_volume_controller_firmware:*:*:*:*:*:*:*:*; start including 7.3.0.0; end excluding 7.3.0.7supportedcpe:2.3:o:ibm:security_access_manager_for_mobile_8.0_firmware:8.0.0.1:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_mobile_8.0_firmware:8.0.0.2:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_mobile_8.0_firmware:8.0.0.3:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_mobile_8.0_firmware:8.0.0.5:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.1:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.2:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.3:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.4:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.5:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.6:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.7:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.8:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.2:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.3:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.5:*:*:*:*:*:*:*supportedcpe:2.3:o:ibm:stn6500_firmware:*:*:*:*:*:*:*:*; start including 3.8.0.0; end excluding 3.8.0.07supportedcpe:2.3:o:ibm:stn6500_firmware:*:*:*:*:*:*:*:*; start including 3.9.1.0; end excluding 3.9.1.08supportedcpe:2.3:o:ibm:stn6500_firmware:*:*:*:*:*:*:*:*; start including 4.1.2.0; end excluding 4.1.2.06supportedcpe:2.3:o:ibm:stn6800_firmware:*:*:*:*:*:*:*:*; start including 3.8.0.0; end excluding 3.8.0.07supportedcpe:2.3:o:ibm:stn6800_firmware:*:*:*:*:*:*:*:*; start including 3.9.1.0; end excluding 3.9.1.08supportedcpe:2.3:o:ibm:stn6800_firmware:*:*:*:*:*:*:*:*; start including 4.1.2.0; end excluding 4.1.2.06supportedcpe:2.3:o:ibm:stn7800_firmware:*:*:*:*:*:*:*:*; start including 3.8.0.0; end excluding 3.8.0.07supportedcpe:2.3:o:ibm:stn7800_firmware:*:*:*:*:*:*:*:*; start including 3.9.1.0; end excluding 3.9.1.08supportedcpe:2.3:o:ibm:stn7800_firmware:*:*:*:*:*:*:*:*; start including 4.1.2.0; end excluding 4.1.2.06supportedcpe:2.3:o:ibm:storwize_v3500_firmware:*:*:*:*:*:*:*:*; start including 1.1.0.0; end excluding 7.1.0.11supportedcpe:2.3:o:ibm:storwize_v3500_firmware:*:*:*:*:*:*:*:*; start including 7.2.0.0; end excluding 7.2.0.9supportedcpe:2.3:o:ibm:storwize_v3500_firmware:*:*:*:*:*:*:*:*; start including 7.3.0.0; end excluding 7.3.0.7supportedcpe:2.3:o:ibm:storwize_v3700_firmware:*:*:*:*:*:*:*:*; start including 1.1.0.0; end excluding 7.1.0.11supportedcpe:2.3:o:ibm:storwize_v3700_firmware:*:*:*:*:*:*:*:*; start including 7.2.0.0; end excluding 7.2.0.9supportedcpe:2.3:o:ibm:storwize_v3700_firmware:*:*:*:*:*:*:*:*; start including 7.3.0.0; end excluding 7.3.0.7supportedcpe:2.3:o:ibm:storwize_v5000_firmware:*:*:*:*:*:*:*:*; start including 1.1.0.0; end excluding 7.1.0.11supportedcpe:2.3:o:ibm:storwize_v5000_firmware:*:*:*:*:*:*:*:*; start including 7.2.0.0; end excluding 7.2.0.9supportedcpe:2.3:o:ibm:storwize_v5000_firmware:*:*:*:*:*:*:*:*; start including 7.3.0.0; end excluding 7.3.0.7supportedcpe:2.3:o:ibm:storwize_v7000_firmware:*:*:*:*:*:*:*:*; start including 1.1.0.0; end excluding 1.4.3.5supportedcpe:2.3:o:ibm:storwize_v7000_firmware:*:*:*:*:*:*:*:*; start including 1.5.0.0; end excluding 1.5.0.4supportedcpe:2.3:o:ibm:storwize_v7000_firmware:*:*:*:*:*:*:*:*; start including 7.2.0.0; end excluding 7.2.0.9supportedcpe:2.3:o:ibm:storwize_v7000_firmware:*:*:*:*:*:*:*:*; start including 7.3.0.0; end excluding 7.3.0.7supportedcpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*supportedcpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*supportedcpe:2.3:o:novell:open_enterprise_server:11.0:sp2:*:*:*:linux_kernel:*:*supportedcpe:2.3:o:novell:open_enterprise_server:2.0:sp3:*:*:*:linux_kernel:*:*supportedcpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*supportedcpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*supportedcpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*supportedcpe:2.3:o:oracle:linux:4:*:*:*:*:*:*:*supportedcpe:2.3:o:oracle:linux:5:-:*:*:*:*:*:*supportedcpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*supportedcpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*; end excluding 4.1.1supportedcpe:2.3:o:qnap:qts:4.1.1:-:*:*:*:*:*:*supportedcpe:2.3:o:qnap:qts:4.1.1:build_0927:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux:4.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:6.4:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:6.5:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:7.3:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:7.4:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:5.9_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.4_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.5_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.3_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.4_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.5_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.6_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.7_s390x:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:5.0_ppc:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:5.9_ppc:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.4_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:7.0_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:6.5_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.3_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.4_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.5_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.6_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_power_big_endian_eus:7.7_ppc64:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:7.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:5.6:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:6.2:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_from_rhui:5.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_from_rhui:6.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_from_rhui:7.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_tus:6.5:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*supportedcpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_desktop:12:-:*:*:*:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_server:10:sp3:*:*:ltss:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:ltss:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:ltss:-:*:*supportedcpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*supportedcpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*supportedcpe:2.3:o:suse:linux_enterprise_server:12:-:*:*:*:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*supportedcpe:2.3:o:suse:linux_enterprise_software_development_kit:12:-:*:*:*:*:*:*supportedcpe:2.3:o:vmware:esx:4.0:*:*:*:*:*:*:*supportedcpe:2.3:o:vmware:esx:4.1:*:*:*:*:*:*:*supportedAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.