CVE-2025-3160
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 862
Summary
CVE-2025-3160 is a newly discovered vulnerability affecting Open Asset Import Library Assimp 5.4.3. This issue lies within the Assimp::SceneCombiner::AddNodeHashes function of the File Handler's code/Common/SceneCombiner.cpp file. The manipulation results in an out-of-bounds read, making it a problematic vulnerability. An attacker must be local to exploit this vulnerability, which has already been made public. A patch identified as a0993658f40d8e13ff5823990c30b43c82a5daf0 is recommended to address the issue and prevent potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.