CVE-2023-54342Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-05); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-05: 3Mentions · 2026-05-16: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-05: 3Technical Details · 2026-05-16: 105-0505-16
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-053
Disclosure2Patch1
2026-05-161
Patch1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Eclipse Equinox OSGi Unauth RCE (CVE-2023-54342) A remote code execution (RCE) vulnerability exists in the Eclipse Equinox OSGi console. Unauthenticated attackers can connect via telnet and abuse the fork command to download and execute malicious Java code, allowing them to establish a reverse shell and compromise the server. 👉 Affected: Equinox OSGi 3.8 - 3.18 | Upgrade to 3.19.0

    Post summary

    CVE‑2023‑54342 is an unauthenticated RCE in Eclipse Equinox OSGi console that allows attackers to run arbitrary Java code via telnet. Upgrading to version 3.19.0 removes the vulnerability.

    00020127
    237 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A critical remote code execution vulnerability (CVE-2023-54342) affects Eclipse Equinox OSGi consoles (v3.8–3.18). Unauthenticated attackers can exploit telnet access to execute code remotely. Verify your systems and apply updates urgently. #Cybersecurity

    Post summary

    The post alerts that CVE‑2023‑54342 permits unauthenticated remote code execution via telnet on Eclipse Equinox OSGi consoles, urging users to verify and apply urgent updates.

    00010117
    80 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2023-54342 Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute… https://www.cve.org/CVERecord?id=CVE-2023-54342

    Post summary

    The excerpt reports a new CVE (CVE-2023-54342) describing an RCE in the Eclipse Equinox OSGi console affecting versions 3.8‑3.18, with no follow‑up on exploits, mitigation, or active use.

    00010216
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2023-54342 Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute… https://www.cve.org/CVERecord?id=CVE-2023-54342 ----- Traducción: CVE-2023-54342 Ecl… http://infoflow.cloud`

    Post summary

    The post provides a disclosure of a remote code execution vulnerability affecting Eclipse Equinox OSGi 3.8‑3.18 that allows unauthenticated attackers to execute code via the console interface.

    0000052
    75 followersView on X

Explore more