CVE-2023-29492
novisurvey novi_survey
Published 11 Apr 2023 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 13 Apr 2023, with a remediation deadline of 4 May 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
References
- novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29492 · US Government Resource