Novi Survey Insecure Deserialization Vulnerability
Summary
| CVE | CVE-2023-29492 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-11 05:15:00 UTC |
| Updated | 2023-04-18 02:16:00 UTC |
| Description | Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data. |
Risk And Classification
EPSS: 0.026900000 probability, percentile 0.842910000 (date 2026-07-22)
CISA KEV: Listed on 2023-04-13; due 2023-05-04; ransomware use Unknown
Problem Types: CWE-94
CISA Known Exploited Vulnerability
| Vendor | Novi Survey |
|---|---|
| Product | Novi Survey |
| Name | Novi Survey Insecure Deserialization Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx; https://nvd.nist.gov/vuln/detail/CVE-2023-29492 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Novisurvey | Novi Survey | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| novi survey security advisory apr 2023 | CONFIRM | novisurvey.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 731228 Novi Survey Arbitrary Code Execution Vulnerability