Vulnerability
Novi Survey Insecure Deserialization Vulnerability
Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.
Apply updates per vendor instructions.
CISA description: “Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAbove the FIRST 'patch on a priority schedule' threshold.
No VEX statements published for CVE-2023-29492. Vendors publish VEX (Vulnerability Exploitability eXchange) to assert per-product whether a CVE is actually exploitable in their distribution.
Active exploitation with total impact on essential/support systems