CVE-2017-11743

9.8 CRITICAL
Published: July 31, 2017 Modified: May 13, 2026
View on NVD

Description

MEDHOST Connex contains a hard-coded Mirth Connect admin credential that is used for customer Mirth Connect management access. An attacker with knowledge of the hard-coded credential and the ability to communicate directly with the Mirth Connect management console may be able to intercept sensitive patient information. The admin account password is hard-coded as $K8t1ng throughout the application, and is the same across all installations. Customers do not have the option to change the Mirth Connect admin account password. The Mirth Connect admin account is created during the Connex install. The plaintext account password is hard-coded multiple times in the Connex install and update scripts.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jul/75
Source: cve@mitre.org
Mailing List Third Party Advisory
http://www.securityfocus.com/bid/100086
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2017/Jul/75
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List Third Party Advisory
http://www.securityfocus.com/bid/100086
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry

4 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
EPSS (Exploit Probability)
1.6%
73th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

medhost