QID 730974

Date Published: 2023-11-17

QID 730974: NextGen Mirth Connect Java XStream Remote Code Execution (RCE) Vulnerability

NextGen Mirth Connect is a cross-platform interface engine used in the healthcare industry that enables the management of information using bi-directional sending of many types of messages.

The vulnerability exists because of an incomplete patch for CVE-2023-37679 when processing serialized Java XStream objects. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system.

Affected Versions:
NextGen Mirth Connect prior to 4.4.1

QID Detection Logic:
This unauthenticated QID detects the version of the NextGen Mirth Connect to determine if it is vulnerable.

Successful exploitation allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to NextGen Mirth Connect 4.4.1 or later versions to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730974

    Software Advisories
    Advisory ID Software Component Link
    NextGen Mirth Connect 4.4.1 or later URL Logo github.com/nextgenhealthcare/connect/releases