CVE-2023-43208
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 83% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78, CWE-502
מוצרים מושפעים
nextgen: mirth connect
קישורים
- http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command… ExploitThird Party AdvisoryVDB Entry
- https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerabil… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command… ExploitThird Party AdvisoryVDB Entry
- https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerabil… ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource