KEVIntel
9.8
CVSS
Critical

CVE-2023-43208

PUBLISHED

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is...

Exploited in the wild Used in malware Remote Low complexity No user interaction
Vendor
NextGen Healthcare
Product
Mirth Connect
Published
Oct 26, 2023
EPSS

Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

cisa malware nuclei_scanner metasploit nessus_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-05-20 00:00:00 UTC · Source

Used in malware

Recorded 2026-06-02 14:08:23 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 20, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

mirth_connect_cve_2023_43208

metasploit · Created Unknown

Metasploit module for CVE-2023-43208

Avento/CVE-2023-43208_Detection_PoC

github · Created 2024-11-28 09:03:23 UTC · 2 stars

Use java.net.InetAddress for detection

jakabakos/CVE-2023-43208-mirth-connect-rce-poc

github · Created 2024-03-17 08:44:14 UTC · 3 stars

K3ysTr0K3R/CVE-2023-43208-EXPLOIT

github · Created 2024-03-15 12:03:51 UTC · 24 stars

A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nessus

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit

  • Exploit Used in Malware