← Vulnerability feed

Vulnerability record · CVE-2023-29492 · published 11 April 2023

CVE-2023-29492: Novi Survey code injection allows remote code execution

3rdmill · Novi Survey

Novi Survey before 8.9.43676 contains a code injection flaw (CWE-94) that lets remote attackers execute arbitrary code on the server under the service account. The vendor advisory and CISA KEV entry describe it as an insecure deserialization vulnerability. Because it is network-reachable with no privileges or user interaction, it is a serious pre-auth RCE risk for exposed instances.

9.8 CVSS 3.1 Critical CISA KEV since 13 Apr 2023 EPSS 2.7% · top 14.7% CWE-94 · Code injection
9.8CVSS 3.1 base score
2.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 pre-auth network RCE combined with CISA KEV listing indicates active exploitation and urgent remediation need.

What it is

Novi Survey before 8.9.43676 contains a code injection flaw (CWE-94) that lets remote attackers execute arbitrary code on the server under the service account. The vendor advisory and CISA KEV entry describe it as an insecure deserialization vulnerability. Because it is network-reachable with no privileges or user interaction, it is a serious pre-auth RCE risk for exposed instances.

Impact

An attacker gains arbitrary code execution in the context of the Novi Survey service account, which can lead to full server compromise. The record states this does not provide access to stored survey or response data.

Attack surface

Reachable over the network per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. Any internet- or network-exposed Novi Survey instance below 8.9.43676 is in scope.

Exploitation

CISA added it to KEV on 2023-04-13 with a 2023-05-04 remediation due date, indicating known exploitation; EPSS 30-day probability is 0.0269 (85th percentile). No ransomware campaign use is documented.

What to do

  • Upgrade Novi Survey to 8.9.43676 or later immediately per the vendor advisory.
  • If patching cannot be done at once, remove the instance from internet exposure and restrict access to trusted networks.
  • Run the Novi Survey service under a least-privileged account to limit the impact of code execution.
  • Monitor vendor and CISA guidance for any additional interim mitigations.

Detection

  • Review web server and application logs for unexpected POST requests or deserialization-related errors against Novi Survey endpoints.
  • Monitor for child processes spawned by the Novi Survey service account, especially command shells or scripting interpreters.
  • Alert on outbound network connections originating from the Novi Survey host to unfamiliar destinations.
  • Audit file writes or new executables in Novi Survey application directories and service-account-writable paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-29492 to the Known Exploited Vulnerabilities catalog on 13 April 2023 as "Novi Survey Insecure Deserialization Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 4 May 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29492 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2023-29492), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.