← Vulnerability feed

Vulnerability record · CVE-2023-37679 · published 3 August 2023

CVE-2023-37679: NextGen Mirth Connect command injection enables remote code execution

Nextgen · Mirth Connect

NextGen Mirth Connect v4.3.0 contains a command injection flaw (CWE-77) that lets an unauthenticated remote attacker run arbitrary commands on the hosting server. With a CVSS 3.1 base score of 9.8 and near-maximum EPSS probability, this is a high-value target for initial access. The record names only v4.3.0, so other versions cannot be confirmed as affected from the data given.

9.8 CVSS 3.1 Critical EPSS 99% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
9 Jul 2026Last modified by NVD

Description

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score and 99.9th-percentile EPSS, plus public exploit references, makes this an urgent patch-or-isolate case.

What it is

NextGen Mirth Connect v4.3.0 contains a command injection flaw (CWE-77) that lets an unauthenticated remote attacker run arbitrary commands on the hosting server. With a CVSS 3.1 base score of 9.8 and near-maximum EPSS probability, this is a high-value target for initial access. The record names only v4.3.0, so other versions cannot be confirmed as affected from the data given.

Impact

An attacker gains arbitrary command execution on the Mirth Connect host, which can lead to full server compromise, data theft, and lateral movement into connected healthcare systems. Because the service often handles HL7 traffic, compromise can also expose or tamper with clinical data flows.

Attack surface

The CVSS vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not specify the exact endpoint or parameter, so the precise entry point is not documented in this record.

Exploitation

Public exploit code is referenced (IHTeam advisory tagged Exploit, plus a Packet Storm writeup), and EPSS is 0.99434 (99.9th percentile), indicating very high likelihood of exploitation. The CVE is not listed in CISA KEV, so confirmed in-the-wild use is not established by this record.

What to do

  • Upgrade Mirth Connect to a fixed release as soon as the vendor provides one; v4.3.0 is the only version named as affected here.
  • If patching is not immediately possible, restrict network access to the Mirth Connect administrative and service ports to trusted hosts only.
  • Place the Mirth Connect server behind a reverse proxy or WAF and block unexpected command-like input to exposed endpoints.
  • Run the Mirth Connect service with a least-privilege OS account and limit its outbound network access.
  • Monitor vendor advisories for updated affected-version information, since this record only names v4.3.0.

Detection

  • Monitor Mirth Connect host processes for unexpected child processes spawned by the Java service (e.g., cmd.exe, /bin/sh, curl, wget).
  • Alert on outbound network connections from the Mirth Connect server to unfamiliar external IPs or ports.
  • Review Mirth Connect and web server logs for suspicious request patterns or encoded command strings around the time of anomalous process activity.
  • Baseline normal Mirth Connect behavior and alert on deviations such as new listening ports, new files in web-accessible directories, or unexpected scheduled tasks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-37679 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-43208NextGen Mirth Connect unauthenticated remote code executionNextGen Healthcare Mirth Connect before 4.4.1 is vulnerable to unauthenticated remote code execution. The flaw stems from an incomplete patch of CVE-…KEVEPSS 83%analysed9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed9.8CVE-2025-10035Fortra GoAnywhere MFT License Servlet deserialization to command injectionThe License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2023-37679), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.