Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2023-54344 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2023 |
| Date Published | 2026-05-05 |
| Vendor | Eclipse Foundation |
| Product | Equinox OSGi |
| CVSS Score | 9.8 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to achieve code execution and establish reverse shell connections.
Required Actions
Apply vendor patches or mitigations as soon as available.
Who Is Affected?
This vulnerability affects Equinox OSGi by Eclipse Foundation. Check if your organization uses this software and requires updates.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
