Executive brief
NextGen Healthcare Mirth Connect is vulnerable to unauthenticated remote code execution due to the deserialization of untrusted data. This vulnerability stems from an incomplete patch for CVE-2023-37679 and allows an attacker to execute arbitrary commands via specially crafted requests.
Affected products
- NextGen Healthcare Mirth Connect before 4.4.1
Timeline
- 2023-10-26: disclosed: NVD Published Date
- 2024-05-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-05-20: exploited: Reported as exploited in the wild in CISA KEV catalog