nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-54342 CVE-2023-54342
CRITICAL
Eclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution
Record summary
CVE-2023-54342 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | [3.8 - 3.18] | affected |
Proofs of concept
1Catalogued exploits
ExploitDBOSGi v3.8-3.18 Console - RCEExploitDB exploitby Andrzej Olchawa_ Milenko StarcikNot analyzed1 file
References
3ExploitDB-51878exploit
https://www.exploit-db.com/exploits/51878 VulnCheck Advisory: Eclipse Equinox OSGi 3.8-3.18 Console Remote Code ExecutionThird-party advisory
https://www.vulncheck.com/advisories/eclipse-equinox-osgi-console-remote-code-execution