Junglewise Threat Intelligence

CVE-2023-29492: Novi Survey Insecure Deserialization Vulnerability

CVE-2023-29492 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-04-13

Executive brief

Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute arbitrary code on the server. The exploit occurs within the context of the service account but does not grant direct access to stored survey or response data.

Affected products

  • Novi Survey Novi Survey before 8.9.43676

Timeline

  • 2023-04-11: disclosed
  • 2023-04-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-13: advisory: Vendor advisory published by Novi Survey