Remote Code Execution Vulnerability in Eclipse Equinox OSGi Console Interface
CVE-2023-54342
Key Information:
Badges
What is CVE-2023-54342?
Eclipse Equinox OSGi versions 3.8 through 3.18 are susceptible to a remote code execution vulnerability via the console interface. This flaw enables unauthenticated attackers to exploit the fork command functionality, allowing them to establish a telnet connection to the OSGi console. By performing a telnet handshake and sending fork commands, attackers can download and execute arbitrary Java code, which may lead to a reverse shell connection, thereby compromising the integrity and security of the affected system.
Affected Version(s)
[OSGi [3.8 - 3.18]
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
