« Volver al listado

CVE-2022-38072

Estado: ModificadaAlta (8.8)—

An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-38072",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-38072",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-11T15:53:05.178393Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "talos-cna@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "talos-cna@cisco.com",
      "affectedData": [
        {
          "vendor": "ADMesh",
          "product": "ADMesh",
          "versions": [
            {
              "status": "affected",
              "version": "Master Commit 767a105"
            },
            {
              "status": "affected",
              "version": "v0.98.4"
            }
          ]
        },
        {
          "vendor": "ADMesh",
          "product": "ADMesh",
          "versions": [
            {
              "status": "affected",
              "version": "Master Commit 767a105"
            },
            {
              "status": "affected",
              "version": "v0.98.4"
            }
          ]
        },
        {
          "vendor": "ADMesh",
          "product": "ADMesh",
          "versions": [
            {
              "status": "affected",
              "version": "Master Commit 767a105"
            },
            {
              "status": "affected",
              "version": "v0.98.4"
            }
          ]
        },
        {
          "vendor": "Slic3r",
          "product": "libslic3r",
          "versions": [
            {
              "status": "affected",
              "version": "Master Commit b1a5500"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-04-03T16:15:07.343",
  "references": [
    {
      "url": "https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5f",
      "tags": [
        "Patch"
      ],
      "source": "talos-cna@cisco.com"
    },
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1594",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "talos-cna@cisco.com"
    },
    {
      "url": "https://github.com/admesh/admesh/commit/5fab257268a0ee6f832c18d72af89810a29fbd5f",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2022-1594",
      "tags": [
        "Exploit",
        "Technical Description",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1594",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "talos-cna@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-118"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-129"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master Commit 767a105 and v0.98.4. A specially-crafted stl file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability."
    }
  ],
  "lastModified": "2026-06-17T04:56:02.383",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:admesh_project:admesh:0.98.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA8A8D5A-8011-49C7-9527-213CD58D0AD4"
            },
            {
              "criteria": "cpe:2.3:a:admesh_project:admesh:2022-11-18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "784F7EAF-BC6F-421B-8B95-B15CC7A331D0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:slic3r:libslic3r:b1a5500:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A6DF928-F3A0-46D0-9806-75464C70DD9D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "talos-cna@cisco.com"
}