Junglewise Threat Intelligence

CVE-2023-43208: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

CVE-2023-43208 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-05-20

Executive brief

NextGen Healthcare Mirth Connect is vulnerable to unauthenticated remote code execution due to the deserialization of untrusted data. This vulnerability stems from an incomplete patch for CVE-2023-37679 and allows an attacker to execute arbitrary commands via specially crafted requests.

Affected products

  • NextGen Healthcare Mirth Connect before 4.4.1

Timeline

  • 2023-10-26: disclosed: NVD Published Date
  • 2024-05-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-05-20: exploited: Reported as exploited in the wild in CISA KEV catalog