Vulnerability record · CVE-2023-37679 · published 3 August 2023
CVE-2023-37679: NextGen Mirth Connect command injection enables remote code execution
Nextgen · Mirth Connect
NextGen Mirth Connect v4.3.0 contains a command injection flaw (CWE-77) that lets an unauthenticated remote attacker run arbitrary commands on the hosting server. With a CVSS 3.1 base score of 9.8 and near-maximum EPSS probability, this is a high-value target for initial access. The record names only v4.3.0, so other versions cannot be confirmed as affected from the data given.
Description
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score and 99.9th-percentile EPSS, plus public exploit references, makes this an urgent patch-or-isolate case.
What it is
NextGen Mirth Connect v4.3.0 contains a command injection flaw (CWE-77) that lets an unauthenticated remote attacker run arbitrary commands on the hosting server. With a CVSS 3.1 base score of 9.8 and near-maximum EPSS probability, this is a high-value target for initial access. The record names only v4.3.0, so other versions cannot be confirmed as affected from the data given.
Impact
An attacker gains arbitrary command execution on the Mirth Connect host, which can lead to full server compromise, data theft, and lateral movement into connected healthcare systems. Because the service often handles HL7 traffic, compromise can also expose or tamper with clinical data flows.
Attack surface
The CVSS vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not specify the exact endpoint or parameter, so the precise entry point is not documented in this record.
Exploitation
Public exploit code is referenced (IHTeam advisory tagged Exploit, plus a Packet Storm writeup), and EPSS is 0.99434 (99.9th percentile), indicating very high likelihood of exploitation. The CVE is not listed in CISA KEV, so confirmed in-the-wild use is not established by this record.
What to do
- Upgrade Mirth Connect to a fixed release as soon as the vendor provides one; v4.3.0 is the only version named as affected here.
- If patching is not immediately possible, restrict network access to the Mirth Connect administrative and service ports to trusted hosts only.
- Place the Mirth Connect server behind a reverse proxy or WAF and block unexpected command-like input to exposed endpoints.
- Run the Mirth Connect service with a least-privilege OS account and limit its outbound network access.
- Monitor vendor advisories for updated affected-version information, since this record only names v4.3.0.
Detection
- Monitor Mirth Connect host processes for unexpected child processes spawned by the Java service (e.g., cmd.exe, /bin/sh, curl, wget).
- Alert on outbound network connections from the Mirth Connect server to unfamiliar external IPs or ports.
- Review Mirth Connect and web server logs for suspicious request patterns or encoded command strings around the time of anomalous process activity.
- Baseline normal Mirth Connect behavior and alert on deviations such as new listening ports, new files in web-accessible directories, or unexpected scheduled tasks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-37679 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-37679), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.