CRITICAL

CVE-2023-29492

3rdmill Novi Survey 2023-04-11 CVSS v3.1
CVSS
9.8
KEV

Description

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

Summary dbcve.org

Novi Survey versions prior to 8.9.43676 contain a remote code execution flaw that allows remote attackers to execute arbitrary code on the server in the context of the application service account. The underlying weakness (e.g., injection, deserialization) is not detailed in the advisory, but the impact is full server-side code execution reachable by remote attackers. The advisory notes the issue does not grant access to stored survey or response data, indicating the compromise is scoped to the application/service account context rather than the underlying data store.

Mitigation

Upgrade Novi Survey to version 8.9.43676 or later as a priority, given the critical CVSS 9.8 score and unauthenticated remote exploitability. Following the patch, review the service account's privileges to enforce least-privilege and audit the host for indicators of prior compromise.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

2.69%
Probability of exploitation in next 30 days
85.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE