Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data

Mirth Connect versions prior to 4.4.1 are vulnerable to CVE-2023-43208, a bypass for an RCE vulnerability.

Open source data integration platform Mirth Connect is affected by a remote code execution vulnerability that can be exploited without authentication, cybersecurity firm Horizon3.ai warns.

Developed by NextGen HealthCare, Mirth Connect is a cross-platform interface engine that healthcare organizations rely on for information management.

Tracked as CVE-2023-43208, the newly disclosed issue is a bypass for a critical-severity RCE flaw (CVE-2023-37679, CVSS score of 9.8) that was disclosed in August 2023 and which was addressed with the release of Mirth Connect version 4.4.0.

According to Horizon3.ai, CVE-2023-37679 was said to only impact Mirth Connect instances using Java 8 or below, but further analysis of the vulnerability has revealed that, in fact, all Mirth Connect installs are impacted, regardless of the Java version they use.

Furthermore, the cybersecurity firm’s investigation has revealed that the patch for CVE-2023-37679 can be bypassed, and reported the findings to NextGen HealthCare, which released Mirth Connect version 4.4.1 to address the new issue.

“This is an easily exploitable, unauthenticated remote code execution vulnerability. Attackers would most likely exploit this vulnerability for initial access or to compromise sensitive healthcare data,” Horizon3.ai says.

Advertisement. Scroll to continue reading.

For the time being, Horizon3.ai refrains from releasing technical details or an exploit for CVE-2023-43208, but warns that the methods for exploitation are well known.

“We have verified that Mirth Connect versions going as far back as 2015/2016 are vulnerable,” the cybersecurity firm notes.

Horizon3.ai also points out that Mirth Connect appears to be deployed mostly on Windows machines, where it typically runs with System privileges, suggesting that the impact of a successful attack would be critical.

Additionally, the cybersecurity firm notes that it has identified more than 1,200 unique Mirth Connect instances that are directly accessible from the internet.

Mirth Connect users are advised to update to version 4.4.1 of the platform as soon as possible.

Related: Dozens of RCE Vulnerabilities Impact Milesight Industrial Router

Related: Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins

Related: Fortinet Patches Critical RCE Vulnerability in FortiNAC

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.