CVE-2023-43208
KEV RANSOMWARECRITICAL 9.8EPSS 82.7%
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 82.71% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-05-20, used in ransomware campaigns
- Nuclei
- critical
- Published
- 2023-10-26
- Updated
- 2025-10-21
Proof-of-concept exploits (17)
- http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.…
- https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerability-cve-202…
- Avento/CVE-2023-43208_Detection_PoC2★ · 2024-11-28
- J4F9S5D2Q7/CVE-2023-43208-MIRTHCONNECT0★ · 2024-06-09
- K3ysTr0K3R/CVE-2023-43208-EXPLOIT29★ · 2026-04-30
- gotr00t0day/NextGen-Mirth-Connect-Exploit9★ · 2024-03-19
- jakabakos/CVE-2023-43208-mirth-connect-rce-poc7★ · 2024-03-18
- 4nuxd/CVE-2023-43208
- Criz117/CVE-2023-43208-PoC
- D3m0nicw0lf/CVE-2023-43208
- Humberto-pixel/CVE-2023-43208-PoC
- LunaLynx12/cve-2023-43208-poc
- MKIRAHMET/PoC-2023-43208
- Pegasus0xx/CVE-2023-43208
- az4rvs/Mirth-Connect-CVE-2023-43208
- kyakei/CVE-2023-43208
- predyy/CVE-2023-43208