equinox Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with equinox products.
Products
- [OSGi2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-54344CRITICAL | Eclipse Equinox OSGi 3.7.2 Remote Code Execution via ConsoleEclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to achieve code execution and establish reverse shell connections. CWE-306May 5, 2026 | CVSS9.3v4.0 | EPSS0.55% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-54342CRITICAL | Eclipse Equinox OSGi 3.8-3.18 Console Remote Code ExecutionEclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection. CWE-306May 5, 2026 | CVSS9.3v4.0 | EPSS0.455% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |