CVE-2025-2592
CVSS 3.1 Score 8 of 10 (high)
Details
Published Mar 21, 2025
CWE ID 352
Summary
CVE-2025-2592 is a critical vulnerability affecting Open Asset Import Library Assimp 5.4.3. The issue resides in the CSMImporter::InternReadFile function of the file CSM/CSMLoader.cpp. This vulnerability results in a heap-based buffer overflow, making it susceptible to remote exploitation. The exploit has been made public, posing a significant risk. To mitigate this threat, it is strongly advised to install the patch, which carries the commit hash 2690e354da0c681db000cfd892a55226788f2743.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OpenMRS
Affected Vendors
- OpenMRS