SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-29492

Novi Survey Insecure Deserialization Vulnerability

KEVCRITICAL 9.8EPSS 2.69%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 4 May 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.69% probability · 85th percentile
CISA KEV
Listed 13 April 2023 · due 4 May 2023
Weakness
CWE-94
Affected
3rdmill/novi survey
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx; https://nvd.nist.gov/vuln/detail/CVE-2023-29492

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.