CVE-2023-29492
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Novi Survey Insecure Deserialization Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-94
מוצרים מושפעים
3rdmill: novi survey
קישורים
- https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx Vendor Advisory
- https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource