CVE-2023-43208: NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
Other sources
NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NextGen Mirth Connectto a version that resolves this vulnerability.Fixed in 4.4.1 - Compensating control
If vendor mitigations are unavailable, discontinue use of NextGen Mirth Connect (stop running the product and remove it from production environments)
Event History
Frequently Asked Questions
What is CVE-2023-43208?
CVE-2023-43208 is a vulnerability in NextGen Healthcare Mirth Connect before version 4.4.1 that allows unauthenticated remote code execution.
What is the severity of CVE-2023-43208?
CVE-2023-43208 has a severity rating of 9.8 (Critical).
How does CVE-2023-43208 affect NextGen Healthcare Mirth Connect?
CVE-2023-43208 affects NextGen Healthcare Mirth Connect before version 4.4.1, allowing unauthenticated remote code execution.
How can I fix CVE-2023-43208?
To fix CVE-2023-43208, you should update NextGen Healthcare Mirth Connect to version 4.4.1 or newer.
Where can I find more information about CVE-2023-43208?
You can find more information about CVE-2023-43208 at https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerability-cve-2023-43208/