Back to Labs
Security Advisory

CVE-2023-29492

About

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

Weakness (CWE):CWE-94

Rainforest analyst review

Novi Survey before 8.9.43676 allows a remote attacker to execute arbitrary code on the server, running in the context of the service account. Unauthenticated and requiring no user interaction, this is a straightforward remote code execution against the application host. The advisory does add one scoping detail worth carrying forward: it does not, by itself, grant access to stored survey or response data.

Unauthenticated RCE is the top tier of what attackers hunt for, and code execution as the service account gives a solid foothold on the host regardless of the data-access caveat, defenders should read that caveat as 'the initial blast radius is the host, not necessarily the survey database' rather than as a reason to relax. Clean unauthenticated RCE in a named product is the kind of thing that gets weaponized and scanned for once details circulate.

Our angle is inventory plus exposure: identify any Novi Survey instances below 8.9.43676 and, critically, which are internet-reachable, since those are the ones at immediate risk. We would prioritize patching the exposed set hard, and constrain the service account's privileges so that RCE in that context is as contained as possible, limiting how far an attacker can pivot from the initial foothold.

References

Related CVEs

Frequently asked questions

What is CVE-2023-29492?

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

How severe is CVE-2023-29492?

CVE-2023-29492 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2023-29492 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-29492?

Public advisories list the following as affected: novi survey. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-29492?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email