TopVuln

High-risk vulnerability digests

CVE-2023-54342

  • CRITICAL

Eclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution

Details

CVSS v3
9.8
CVSS v4
9.3
NVD published
2026-05-05 12:16:15
EPSS
0.2% probability · 48.5th percentile — 2026-05-12
Affected versions
Eclipse Equinox OSGi versions 3.8 through 3.18
Summary
This vulnerability allows unauthenticated remote attackers to execute arbitrary code on systems running affected Eclipse Equinox OSGi. Attackers can connect to the exposed OSGi console via telnet and exploit the fork command functionality to run malicious code. Successful exploitation leads to full system compromise and remote control by attackers.
Remediation
Update Eclipse Equinox OSGi to a version outside the affected 3.8 to 3.18 range that patches this vulnerability. Restrict public network access to the OSGi console port to only authorized trusted sources until the update is applied. Disable the OSGi console if it is not actively used by your organization.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.