Vulnerability record · CVE-2023-29492 · published 11 April 2023
CVE-2023-29492: Novi Survey code injection allows remote code execution
3rdmill · Novi Survey
Novi Survey before 8.9.43676 contains a code injection flaw (CWE-94) that lets remote attackers execute arbitrary code on the server under the service account. The vendor advisory and CISA KEV entry describe it as an insecure deserialization vulnerability. Because it is network-reachable with no privileges or user interaction, it is a serious pre-auth RCE risk for exposed instances.
Description
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 pre-auth network RCE combined with CISA KEV listing indicates active exploitation and urgent remediation need.
What it is
Novi Survey before 8.9.43676 contains a code injection flaw (CWE-94) that lets remote attackers execute arbitrary code on the server under the service account. The vendor advisory and CISA KEV entry describe it as an insecure deserialization vulnerability. Because it is network-reachable with no privileges or user interaction, it is a serious pre-auth RCE risk for exposed instances.
Impact
An attacker gains arbitrary code execution in the context of the Novi Survey service account, which can lead to full server compromise. The record states this does not provide access to stored survey or response data.
Attack surface
Reachable over the network per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication and no user interaction are required. Any internet- or network-exposed Novi Survey instance below 8.9.43676 is in scope.
Exploitation
CISA added it to KEV on 2023-04-13 with a 2023-05-04 remediation due date, indicating known exploitation; EPSS 30-day probability is 0.0269 (85th percentile). No ransomware campaign use is documented.
What to do
- Upgrade Novi Survey to 8.9.43676 or later immediately per the vendor advisory.
- If patching cannot be done at once, remove the instance from internet exposure and restrict access to trusted networks.
- Run the Novi Survey service under a least-privileged account to limit the impact of code execution.
- Monitor vendor and CISA guidance for any additional interim mitigations.
Detection
- Review web server and application logs for unexpected POST requests or deserialization-related errors against Novi Survey endpoints.
- Monitor for child processes spawned by the Novi Survey service account, especially command shells or scripting interpreters.
- Alert on outbound network connections originating from the Novi Survey host to unfamiliar destinations.
- Audit file writes or new executables in Novi Survey application directories and service-account-writable paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-29492 to the Known Exploited Vulnerabilities catalog on 13 April 2023 as "Novi Survey Insecure Deserialization Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 4 May 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx | Vendor Advisory |
| https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29492 | US Government Resource |
Track CVE-2023-29492 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-29492), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.