Critical Flaw in NextGen's Mirth Connect Could Expose Healthcare Data
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-37679 | A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. NVD description · AI analysis pending | 9.8 | 99% | PoC |
| — | |
| CVE-2023-43208 | Unauthenticated Deserialization RCE in NextGen Healthcare Mirth Connect CVE-2023-43208 is an unauthenticated remote code execution flaw in NextGen Healthcare Mirth Connect, a widely used healthcare integration engine, caused by incomplete patching of the earlier CVE-2023-37679 deserialization vulnerability. An attacker can trigger it by sending crafted serialized data to the network-exposed Mirth Connect service, requiring no authentication or user interaction (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N). Successful exploitation yields arbitrary code execution on the server, giving attackers a foothold in hospital and health-system networks that Mirth Connect uses to move clinical data (including PHI) between systems. All deployments running Mirth Connect versions before 4.4.1 are affected. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-05-20 with known ransomware use, public proof-of-concept exploits exist, and EPSS estimates an 82.7% chance of exploitation within 30 days. Do: Upgrade Mirth Connect to version 4.4.1 or later as the CISA KEV required action, or discontinue use if upgrades are unavailable. Identify and restrict internet-exposed Mirth Connect instances (the service is commonly reachable on its web/admin interface), and hunt for signs of compromise given confirmed ransomware use. Because this bypasses the earlier CVE-2023-37679 fix, verify patch levels directly rather than assuming prior remediation. | 9.8 | 83% | KEV ransomware PoC ×2 |
| large≈10,000–30,000 internet-exposed Mirth Connect instances, plus many more internal deployments at thousands of hospitals and health systems |
Full article330 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 26, 2023Vulnerability / Network Security
Users of Mirth Connect, an open-source data integration platform from NextGen HealthCare, are being urged to update to the latest version following the discovery of an unauthenticated remote code execution vulnerability.
Tracked as CVE-2023-43208, the vulnerability has been addressed in version 4.4.1 released on October 6, 2023.
"This is an easily exploitable, unauthenticated remote code execution vulnerability," Horizon3.ai's Naveen Sunkavally said in a Wednesday report. "Attackers would most likely exploit this vulnerability for initial access or to compromise sensitive healthcare data."
Called the "Swiss Army knife of healthcare integration," Mirth Connect is a cross-platform interface engine used in the healthcare industry to communicate and exchange data between disparate systems in a standardized manner.
Additional technical details about the flaw have been withheld in light of the fact that Mirth Connect versions going as far back as 2015/2016 have been found to be vulnerable to the issue.
It's worth noting that CVE-2023-43208 is a patch bypass for CVE-2023-37679 (CVSS score: 9.8), a critical remote command execution (RCE) vulnerability in the software that allows attackers to execute arbitrary commands on the hosting server.
While CVE-2023-37679 was described by its maintainers as only affecting servers running Java 8, Horizon3.ai's analysis found that all instances of Mirth Connect, regardless of the Java version, were susceptible to the problem.
The criticality of the issue arises from the fact that Mirth Connect appears to be most commonly deployed on Windows endpoints with SYSTEM user privileges, potentially enabling threat actors to completely take over vulnerable installations.
Given the ease with which the vulnerability can be trivially abused, coupled with the fact that the exploitation methods are well known, it's recommended to update Mirth Connect, particularly that are publicly accessible over the internet, to version 4.4.1 as soon as possible to mitigate potential threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/10/critical-flaw-in-nextgens-mirth-connect.html