CVE-2023-54342
CRITICALEclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2023-54342. PoCs published by Andrzej Olchawa_ Milenko Starcik.
AI-analyzed exploit summary This exploit leverages a vulnerability in OSGi v3.8-3.18 to achieve remote code execution by delivering a reverse shell payload via a multi-stage attack involving a telnet handshake and HTTP server for payload delivery.
Description
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.
Exploits (1)
This exploit leverages a vulnerability in OSGi v3.8-3.18 to achieve remote code execution by delivering a reverse shell payload via a multi-stage attack involving a telnet handshake and HTTP server for payload delivery.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H