Remote Code Execution Vulnerability in Eclipse Equinox OSGi by Eclipse Foundation
CVE-2023-54344
Key Information:
Badges
What is CVE-2023-54344?
Eclipse Equinox OSGi versions 3.7.2 and earlier contain a vulnerability that permits attackers to execute arbitrary commands remotely. By connecting to the OSGi console port, unauthenticated users can send crafted payloads encoded in base64, wrapped within fork directives, enabling them to execute shell commands. This exploitation leads to the potential establishment of reverse shell connections, posing serious risks to system security. Organizations using affected versions should take immediate action to remediate this vulnerability to protect their environments from potential attacks.
Affected Version(s)
[OSGi <= 3.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
