CVE-2023-43208
KEV ransomware PoC ×2large1Unauthenticated Deserialization RCE in NextGen Healthcare Mirth Connect
CISA: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
CVE-2023-43208 is an unauthenticated remote code execution flaw in NextGen Healthcare Mirth Connect, a widely used healthcare integration engine, caused by incomplete patching of the earlier CVE-2023-37679 deserialization vulnerability. An attacker can trigger it by sending crafted serialized data to the network-exposed Mirth Connect service, requiring no authentication or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). Successful exploitation yields arbitrary code execution on the server, giving attackers a foothold in hospital and health-system networks that Mirth Connect uses to move clinical data (including PHI) between systems. All deployments running Mirth Connect versions before 4.4.1 are affected. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-05-20 with known ransomware use, public proof-of-concept exploits exist, and EPSS estimates an 82.7% chance of exploitation within 30 days.
What to do: Upgrade Mirth Connect to version 4.4.1 or later as the CISA KEV required action, or discontinue use if upgrades are unavailable. Identify and restrict internet-exposed Mirth Connect instances (the service is commonly reachable on its web/admin interface), and hunt for signs of compromise given confirmed ransomware use. Because this bypasses the earlier CVE-2023-37679 fix, verify patch levels directly rather than assuming prior remediation.
| NextGen Healthcare Mirth Connect | All versions before 4.4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
- Affected
- NextGen Healthcare Mirth Connect
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- nextgen
- Products
- mirth connect
- Weakness
- CWE-78, CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H