216.73.216.6

CVE-2023-54342

· Published 05/05/2026 12:16 · Modified 05/05/2026 19:47

Labels: CVE-2023-54342 2026-05-05CVE-2023-54342CWE-306[email protected]

Essential information

Published
05/05/2026 12:16
Modified
05/05/2026 19:47
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
eclipse / equinox osgi cpe:2.3:a:eclipse:equinox_osgi:3.8-3.18:*:*:*:*:*:*:*

References