news.mlab.sh
Back to the feed
vulnerability

NextGen Healthcare Mirth Connect

High
Summary

NextGen Healthcare’s Mirth Connect versions 4.7.1 and earlier are vulnerable to SQL injection and XXE injection attacks, potentially leading to data exfiltration and denial-of-service conditions. The CISA has issued an advisory urging immediate updates to version 4.7.2 or later to mitigate these risks. The vulnerabilities could impact healthcare organizations worldwide.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding critical vulnerabilities in NextGen Healthcare’s Mirth Connect software. Specifically, versions 4.7.1 and earlier are susceptible to both SQL injection and XML External Entity Reference (XXE) injection attacks. Successful exploitation could allow an attacker to steal stored credentials from connected systems, write arbitrary files, and cause a denial-of-service condition. The advisory highlights that these vulnerabilities could be exploited by threat actors to gain unauthorized access to sensitive healthcare data.

NextGen Healthcare Mirth Connect, along with NextGen Healthcare, are affected by these vulnerabilities. The CISA recommends that all users immediately update to version 4.7.2 or later to address these security flaws. The advisory emphasizes the importance of proactive security measures to minimize the risk of exploitation.

CISA recommends organizations take defensive measures, including minimizing network exposure for control system devices, isolating control system networks from business networks, and utilizing more secure remote access methods like VPNs (while recognizing VPN vulnerabilities). The CISA also provides additional resources on ICS cybersecurity best practices on their website at cisa.gov/ics, including a technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Furthermore, CISA advises organizations to implement robust cybersecurity strategies and to report any suspected malicious activity to CISA for tracking and correlation. Finally, the agency reminds users to be vigilant against social engineering attacks, discouraging clicking unsolicited links and attachments and providing resources for avoiding email scams and social engineering attacks.

Read the full article at CISA Advisories