CVE-2025-2152 is a critical heap-based buffer overflow vulnerability (CWE-122) in Open Asset Import Library (Assimp) version 5.4.3, specifically within the ConvertToUTF8 function of the BaseImporter.cpp file. This flaw allows for remote code execution, as indicated by its CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 95/100. The vulnerability has been publicly disclosed, meaning exploit code is available, though it is not currently listed in the CISA KEV catalog or major exploit databases like Metasploit or ExploitDB. While there is some community discussion, media coverage is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.4.3CPE matchmatch criteria | cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.