CVE-2023-29492Active Exploitation(3rdmill / novi_survey)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch 3rdmill novi_survey systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-05-04. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • novi_survey

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
novi_survey

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-16: 1Active Exploitation · 2026-03-16: 1Patch / Workaround · 2026-03-16: 103-16
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • David@davidsheyi
    Active Exploitation

    2/ The LockBit gang, responsible for thousands of attacks, exploits CVE-2023-29492. Patch systems regularly to stay ahead. #InfoSec #CyberAttack

    Post summary

    The LockBit gang is actively exploiting CVE-2023-29492; organizations should patch systems promptly to mitigate the threat.

    1000086
    555 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App3rdmillnovi_survey---

Explore more