CVE-2023-29492 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 2.7% (pctl 85)
Patch first
On CISA KEV — known exploited in the wild, due 2023-05-04.
Description
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.69% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | yes — remediate by 2023-05-04 |
| Public exploit | none known |
| Published | 2023-04-11 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Novi Survey Insecure Deserialization Vulnerability |
|---|---|
| Added | 2023-04-13 |
| Due | 2023-05-04 |
| Vendor / product | Novi Survey / Novi Survey |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| 3rdmill | novi survey |
References
→ the Explorer · watch your stack · NVD