peter bassill · operator
$ cve CVE-2023-29492 JSON

CVE-2023-29492 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 2.7% (pctl 85)

Patch first

On CISA KEV — known exploited in the wild, due 2023-05-04.

Description

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.69% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-94
On CISA KEVyes — remediate by 2023-05-04
Public exploitnone known
Published2023-04-11
Last modified2026-06-17

CISA KEV

NameNovi Survey Insecure Deserialization Vulnerability
Added2023-04-13
Due2023-05-04
Vendor / productNovi Survey / Novi Survey
Ransomware usenone reported

Affected (1)

VendorProduct
3rdmillnovi survey

References

→ the Explorer  ·  watch your stack  ·  NVD