Vulnerabilities
1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-29492 | Unauthenticated Deserialization RCE in 3rd Mill Novi Survey Novi Survey, a survey platform from 3rd Mill, fails to safely handle untrusted deserialization (CWE-94), letting unauthenticated remote attackers execute arbitrary code on the server. Because the flaw is network-reachable and requires no privileges or user interaction (CVSS 9.8), any exposed Novi Survey instance running a version before 8.9.43676 can be targeted directly over HTTP. A successful attacker gains code execution in the context of the service account running the application, though the flaw does not grant access to stored survey or response data. Organizations hosting Novi Survey themselves are affected; the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-13 following reports of active exploitation, with an EPSS of about 2.7% (85th percentile). Ransomware association is currently unknown, and no public proof-of-concept is available. Do: Upgrade Novi Survey to version 8.9.43676 or later per vendor instructions, prioritizing instances exposed to the internet. In the meantime, restrict network access to the survey application and review service account activity and process logs for signs of compromise, since successful exploitation runs code under that account. Because the flaw does not expose stored survey data, incident review should focus on service-level code execution rather than data access. | 9.8 | 3% | KEV |
| nichelikely hundreds to low thousands of internet-exposed instances (unknown; no public install counts or scan data) |