ZeroHour

CVE-2023-29492

KEVniche

Unauthenticated Deserialization RCE in 3rd Mill Novi Survey

CISA: Novi Survey Insecure Deserialization Vulnerability

CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
KEV added
AI analysis

Novi Survey, a survey platform from 3rd Mill, fails to safely handle untrusted deserialization (CWE-94), letting unauthenticated remote attackers execute arbitrary code on the server. Because the flaw is network-reachable and requires no privileges or user interaction (CVSS 9.8), any exposed Novi Survey instance running a version before 8.9.43676 can be targeted directly over HTTP. A successful attacker gains code execution in the context of the service account running the application, though the flaw does not grant access to stored survey or response data. Organizations hosting Novi Survey themselves are affected; the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-13 following reports of active exploitation, with an EPSS of about 2.7% (85th percentile). Ransomware association is currently unknown, and no public proof-of-concept is available.

What to do: Upgrade Novi Survey to version 8.9.43676 or later per vendor instructions, prioritizing instances exposed to the internet. In the meantime, restrict network access to the survey application and review service account activity and process logs for signs of compromise, since successful exploitation runs code under that account. Because the flaw does not expose stored survey data, incident review should focus on service-level code execution rather than data access.

Affected
3rd Mill Novi Surveyall versions prior to 8.9.43676
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed instances (unknown; no public install counts or scan data) — Novi Survey is a specialized commercial survey platform typically deployed as one instance per organization rather than a mass-market product, so affected exposure is plausibly limited to a modest number of self-hosted, internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

CISA Known Exploited Vulnerability
Affected
Novi Survey Novi Survey
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
3rdmill
Products
novi survey
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news