CVE-2025-5202 is an out-of-bounds read vulnerability in Open Asset Import Library (Assimp) version 5.4.3, specifically within the HL1MDLLoader::validate_header function. This flaw carries a high severity CVSS score of 7.8, indicating a significant risk, and can lead to high impact on confidentiality, integrity, and availability if exploited. While exploitation requires local access, public exploit details are available, though no active exploitation or widespread community discussion has been observed. The project plans to address this and other fuzzer-identified bugs in a future release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.4.3CPE matchmatch criteria | cpe:2.3:a:assimp:assimp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.