CVE Database · CVE-2023-43208
CVSS v3.1
9.8
EPSS
82.71%
Published
Oct 26, 2023
Modified
Oct 31, 2025
CISA Known Exploited Vulnerability
Added: 2024-05-20 · Due: 2024-06-10
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Public PoC / Exploit (10)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (1)
References (5)