CVE-2023-37679: Command Injection
Published Aug 3, 2023
·Updated
A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.
Affected Software
1 affected component
NextGen Mirth Connect=4.3.0
Event History
Aug 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
03:15 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-37679?
The severity of CVE-2023-37679 is critical.
2
What is the affected software for CVE-2023-37679?
The affected software for CVE-2023-37679 is NextGen Mirth Connect v4.3.0.
3
How does CVE-2023-37679 allow attackers to execute arbitrary commands?
CVE-2023-37679 allows attackers to execute arbitrary commands by exploiting a remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0.
4
Are there any known references for CVE-2023-37679?
Yes, there are the following references for CVE-2023-37679: http://nextgen.com, https://www.ihteam.net/advisory/mirth-connect, http://mirth.com.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-37679?
The Common Weakness Enumeration (CWE) ID for CVE-2023-37679 is 77.