NextGen Healthcare Mirth Connect
Summary
NextGen Healthcare's Mirth Connect software, specifically versions 4.7.1 and earlier, contains critical vulnerabilities that could allow attackers to exfiltrate data or cause denial-of-service conditions. Successful exploitation of these flaws, including SQL Injection and XML External Entity (XXE) vulnerabilities, can lead to the disclosure of stored credentials, arbitrary file writes, and system disruption.
IFF Assessment
The identified vulnerabilities in NextGen Healthcare's Mirth Connect software pose a significant risk to organizations, allowing for data exfiltration and service disruption.
Severity
The CVSS score of 8.3 indicates a HIGH severity, reflecting the potential for an attacker to gain significant access and control, leading to data breaches and operational disruption. The reported vulnerabilities include SQL Injection and XXE, which are potent attack vectors.
Defender Context
This alert highlights critical vulnerabilities in Mirth Connect, a widely used healthcare integration engine. Defenders in the healthcare sector must prioritize patching or updating to the latest versions to mitigate risks of data exfiltration and denial-of-service attacks. Organizations should also review their network segmentation and access controls for systems using Mirth Connect.