{"cvss":9.8,"datePublished":"2024-05-20","dateUpdated":"2024-05-20","description":"NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.","dueDate":"2024-06-10","id":"CVE-2023-43208","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status.   For more information, please see: https://github.com/nextgenhealthcare/connect/wiki/4.4.1---What%27s-New ;  https://nvd.nist.gov/vuln/detail/CVE-2023-43208","product":"Mirth Connect","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"CRITICAL","source":"cisa_known_exploited","title":"NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability","vendor":"NextGen Healthcare"}