HTTP: Nextgen Mirth Connect XStreamSerializer Insecure Deserialization

This signature detects attempts to exploit a known vulnerability against Nextgen Mirth Connect. A successful attack can lead to arbitrary code execution.

Extended Description

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

Affected Products

Nextgen mirth_connect

Short Name
HTTP:CTS:NEXTGEN-MIRTH-INSEC
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2023-37679 CVE-2023-43208 Connect Deserialization Insecure Mirth Nextgen XStreamSerializer
Release Date
04/01/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3691
False Positive
Unknown
Vendors

Nextgen

Found a potential security threat?