Aller au contenu

Fiche vulnérabilité

CVE-2023-43208 : faille exploitée nextgen mirth connect (CVSS 9.8)

Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
26 oct. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • nextgen mirth connect

Correctif et mesures

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Références

Rechercher une autre vulnérabilité dans la base CVE