ZeroHour

CVE-2023-43208

KEV ransomware PoC ×2large1

Unauthenticated Deserialization RCE in NextGen Healthcare Mirth Connect

CISA: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
83%p100
Published
()
KEV added
AI analysis

CVE-2023-43208 is an unauthenticated remote code execution flaw in NextGen Healthcare Mirth Connect, a widely used healthcare integration engine, caused by incomplete patching of the earlier CVE-2023-37679 deserialization vulnerability. An attacker can trigger it by sending crafted serialized data to the network-exposed Mirth Connect service, requiring no authentication or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). Successful exploitation yields arbitrary code execution on the server, giving attackers a foothold in hospital and health-system networks that Mirth Connect uses to move clinical data (including PHI) between systems. All deployments running Mirth Connect versions before 4.4.1 are affected. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-05-20 with known ransomware use, public proof-of-concept exploits exist, and EPSS estimates an 82.7% chance of exploitation within 30 days.

What to do: Upgrade Mirth Connect to version 4.4.1 or later as the CISA KEV required action, or discontinue use if upgrades are unavailable. Identify and restrict internet-exposed Mirth Connect instances (the service is commonly reachable on its web/admin interface), and hunt for signs of compromise given confirmed ransomware use. Because this bypasses the earlier CVE-2023-37679 fix, verify patch levels directly rather than assuming prior remediation.

Affected
NextGen Healthcare Mirth ConnectAll versions before 4.4.1
Estimated exposure
large≈10,000–30,000 internet-exposed Mirth Connect instances, plus many more internal deployments at thousands of hospitals and health systems — Public internet scans of the Mirth Connect web/admin interface have shown tens of thousands of exposed instances, and the product is a standard HL7 integration engine deployed broadly across healthcare organizations, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

CISA Known Exploited Vulnerability
Affected
NextGen Healthcare Mirth Connect
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
nextgen
Products
mirth connect
Weakness
CWE-78, CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news