Vulnerability record · CVE-2023-43208 · published 26 October 2023
CVE-2023-43208: NextGen Mirth Connect unauthenticated remote code execution
Nextgen · Mirth Connect
NextGen Healthcare Mirth Connect before 4.4.1 is vulnerable to unauthenticated remote code execution. The flaw stems from an incomplete patch of CVE-2023-37679 and involves OS command injection and deserialization of untrusted data. It matters because a network-reachable, pre-auth RCE in an integration engine gives attackers full control of a system that often handles sensitive healthcare data.
Description
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network RCE with a CVSS of 9.8, KEV listing with known ransomware use, and very high EPSS probability make this an urgent patch.
What it is
NextGen Healthcare Mirth Connect before 4.4.1 is vulnerable to unauthenticated remote code execution. The flaw stems from an incomplete patch of CVE-2023-37679 and involves OS command injection and deserialization of untrusted data. It matters because a network-reachable, pre-auth RCE in an integration engine gives attackers full control of a system that often handles sensitive healthcare data.
Impact
An unauthenticated attacker can execute arbitrary code on the Mirth Connect server, leading to full compromise of confidentiality, integrity and availability. In practice this can mean data theft, lateral movement into connected clinical systems, and ransomware deployment.
Attack surface
The vulnerability is network-reachable with no privileges or user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed Mirth Connect instance below 4.4.1 is directly in scope.
Exploitation
It is listed in CISA KEV with known ransomware campaign use, and EPSS gives a 30-day probability of about 0.83 (99.65th percentile). Public exploit references exist, so active exploitation should be assumed.
What to do
- Upgrade Mirth Connect to version 4.4.1 or later immediately.
- If patching is not possible, apply vendor mitigations or discontinue use of the product per CISA guidance.
- Remove Mirth Connect from direct internet exposure and restrict access to trusted management networks.
- Rotate credentials and secrets stored or used by the Mirth Connect server after patching.
- Monitor for and investigate any signs of prior compromise before restoring normal operations.
Detection
- Hunt for unexpected child processes spawned by the Mirth Connect Java process, especially shells and command interpreters.
- Review Mirth Connect server logs and web access logs for anomalous requests or deserialization-related errors.
- Monitor outbound network connections from Mirth Connect hosts to unfamiliar external addresses.
- Check for newly created files, scheduled tasks or services on Mirth Connect hosts that are not part of normal operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-43208 to the Known Exploited Vulnerabilities catalog on 20 May 2024 as "NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 10 June 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerability-cve-2023-43208/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerability-cve-2023-43208/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-43208 | US Government Resource |
Track CVE-2023-43208 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-43208), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.