CVE-2022-38072 is a high-severity vulnerability (CVSS 8.8) affecting ADMesh and Slic3r products, stemming from improper array index validation in the stl_fix_normal_directions function. This flaw allows a specially crafted STL file to trigger a heap buffer overflow, potentially leading to complete compromise of confidentiality, integrity, and availability if a user opens a malicious file. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability presents a significant risk due to its high impact and low attack complexity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.98.4CPE matchmatch criteria | cpe:2.3:a:admesh_project:admesh:0.98.4:*:*:*:*:*:*:* | ||
2022-11-18CPE matchmatch criteria | cpe:2.3:a:admesh_project:admesh:2022-11-18:*:*:*:*:*:*:* | ||
b1a5500CPE matchmatch criteria | cpe:2.3:a:slic3r:libslic3r:b1a5500:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.