CVE-2023-43208

CRITICAL KEV RANSOMWARE NUCLEI

NextGen Healthcare Mirth Connect <4.4.1 - RCE

Title source: llm

Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

Exploits (15)

nomisec WORKING POC 23 stars
by K3ysTr0K3R · remote
https://github.com/K3ysTr0K3R/CVE-2023-43208-EXPLOIT
nomisec WORKING POC 3 stars
by jakabakos · remote
https://github.com/jakabakos/CVE-2023-43208-mirth-connect-rce-poc
nomisec WORKING POC 2 stars
by Avento · infoleak
https://github.com/Avento/CVE-2023-43208_Detection_PoC
nomisec WORKING POC 1 stars
by Criz117 · poc
https://github.com/Criz117/CVE-2023-43208-PoC
nomisec WORKING POC 1 stars
by predyy · remote
https://github.com/predyy/CVE-2023-43208
nomisec WORKING POC 1 stars
by kyakei · remote
https://github.com/kyakei/CVE-2023-43208
nomisec WORKING POC
by Humberto-pixel · remote
https://github.com/Humberto-pixel/CVE-2023-43208-PoC
nomisec WORKING POC
by LunaLynx12 · poc
https://github.com/LunaLynx12/cve-2023-43208-poc
nomisec WORKING POC
by 4nuxd · poc
https://github.com/4nuxd/CVE-2023-43208
nomisec WORKING POC
by az4rvs · remote
https://github.com/az4rvs/Mirth-Connect-CVE-2023-43208
nomisec WORKING POC
by D3m0nicw0lf · remote
https://github.com/D3m0nicw0lf/CVE-2023-43208
nomisec WORKING POC
by MKIRAHMET · remote
https://github.com/MKIRAHMET/PoC-2023-43208
nomisec WORKING POC
by Pegasus0xx · remote
https://github.com/Pegasus0xx/CVE-2023-43208
nomisec SCANNER
by J4F9S5D2Q7 · poc
https://github.com/J4F9S5D2Q7/CVE-2023-43208-MIRTHCONNECT

Nuclei Templates (1)

NextGen Healthcare Mirth Connect - Remote Code Execution
CRITICALby princechaddha
Shodan: title:"mirth connect administrator" || http.title:"mirth connect administrator"
FOFA: title="mirth connect administrator"

Scores

CVSS v3 9.8
EPSS 0.9442
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-05-20
VulnCheck KEV 2024-03-07
InTheWild.io 2024-05-20
ENISA EUVD EUVD-2023-47627
Ransomware Use Confirmed
CWE
CWE-78 CWE-502
Status published
Products (1)
nextgen/mirth_connect < 4.4.1
Published Oct 26, 2023
KEV Added May 20, 2024
Tracked Since Feb 18, 2026