SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-43208

NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability

KEVCRITICAL 9.8EPSS 82.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 June 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
82.71% probability · 100th percentile
CISA KEV
Listed 20 May 2024 · due 10 June 2024 · used in ransomware campaigns
Weakness
CWE-78, CWE-502
Affected
nextgen/mirth connect
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://github.com/nextgenhealthcare/connect/wiki/4.4.1---What%27s-New ; https://nvd.nist.gov/vuln/detail/CVE-2023-43208

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.