VulnerabilityAnalyzed
CVE-2023-29492
Novi Survey Insecure Deserialization Vulnerability
KEVCRITICAL 9.8EPSS 2.69%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 4 May 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.69% probability · 85th percentile
- CISA KEV
- Listed 13 April 2023 · due 4 May 2023
- Weakness
- CWE-94
- Affected
- 3rdmill/novi survey
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx; https://nvd.nist.gov/vuln/detail/CVE-2023-29492
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.