← back
CVE-2023-43208

CVE-2023-43208

CVSS 9.8 CRITICALEPSS 82.7%● KEVCWE-502CWE-78
In short

NextGen Healthcare Mirth Connect versions before 4.4.1 allow attackers to run arbitrary code on the server without authentication. This is a critical flaw because anyone on the internet can compromise the entire system.

Technical detail

Unauthenticated remote code execution in Mirth Connect pre-4.4.1 via unsafe deserialization (CWE-502) and command injection (CWE-78). The vulnerability stems from an incomplete patch of CVE-2023-37679, allowing attackers to execute arbitrary commands with server privileges without prior authentication or user interaction.

Summary generated and translated by AI from the official description.
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →