
Comprehensive Visibility for Healthcare
Trusted by Global Healthcare Security Teams
Proactive Healthcare Security Strategies
Exposing Vulnerabilities in
Healthcare Networks
In May 2024, CISA issued an alert about a critical RCE vulnerability (CVE-2023-43208) in NextGen Healthcare’s Mirth Connect platform. This flaw, impacting versions before 4.4.1, allows unauthorized access to sensitive healthcare data and has been exploited by nation-state actors and cybercriminal groups. Censys identified 1,061 publicly exposed Mirth Connect interfaces, highlighting the risk of misconfigurations in healthcare networks. To mitigate these risks, organizations must upgrade Mirth Connect, remove exposed interfaces from the public internet, and implement proactive monitoring for security compliance.

Learn More
Download the reference guide, Securing Healthcare Infrastructure, to gain the tools and knowledge you need to identify and secure critical healthcare protocols, efficiently categorize systems with Censys labels, and execute targeted queries to stay ahead of potential threats.
Related Thinking
-
BlogThe Global State of Internet of Healthcare Things (IoHT) Exposures on Public-Facing Networks
-
AdvisoryAugust 13, 2024 Advisory: Elastic Kibana Prototype Tainting RCE [CVE-2024-37287]
-
BlogMay 22, 2024: Active Exploitation of Healthcare Platform NextGen Mirth Connect RCE (CVE-2023-43208)
-
AdvisoryJuly 2, 2024 Advisory: regreSSHion RCE Vulnerability in OpenSSH Server [CVE-2024-6387]