EXPOSURES › CVE-2023-29492
CVE-2023-29492
HIGH ⌖ ON CISA KEV · EXPLOITEDNovi Survey insecure deserialization vulnerability allows remote code execution.
Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account. This can lead to unauthorized access and potential data compromise. DIB organizations should ensure their systems are updated to mitigate this risk.
Shame score — The vulnerability allows remote code execution, which is a severe security risk and could lead to unauthorized access and data compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.