Critical severity9.8CISA KEVNVD Advisory· Published Oct 26, 2023· Updated Jun 17, 2026
CVE-2023-43208
CVE-2023-43208
Description
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- NextGen Healthcare/Mirth Connectdescription
- Range: <4.4.1
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/176920/Mirth-Connect-4.4.0-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.horizon3.ai/nextgen-mirth-connect-remote-code-execution-vulnerability-cve-2023-43208/nvdExploitThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central FlawThe Hacker News · Aug 10, 2026