Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2023-54344
Eclipse Equinox OSGi 3.7.2 Remote Code Execution via Console
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 9.3 .0055 44.0 —
AFFECTED
Product Versions Fixed
Equinox OSGi unspecified —
TIMELINE
Jan 10 Reserved by VulnCheck
May 5 Published (CNA: VulnCheck)
Oct 1 EXPLOIT PUBLISHED — CVE-2023-54344 (Eclipse Equinox OSGi). Public exploit reference added.
Description
Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to achieve code execution and establish reverse shell connections.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 10, 2026 | Reserved | Reserved by VulnCheck |
| May 5, 2026 | Published | Published (CNA: VulnCheck) |
| October 1, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2023-54344 (Eclipse Equinox OSGi). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Eclipse | Equinox OSGi | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-54344 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.