
Cloud Vulnerability DB
A community-led vulnerabilities database
An out-of-bounds write vulnerability exists in the Admesh stl_fix_normal_directions() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). The vulnerability, identified as CVE-2020-28598, was discovered by Lilith >_> of Cisco Talos and publicly disclosed on April 21, 2021 (Talos Report).
The vulnerability exists in the stl_fix_normal_directions() function where a specially crafted AMF file can trigger an out-of-bounds heap write. The issue occurs because there's no guarantee that (reversed_count % 3) == 0, and given a specific layout of facets/triangles, the same facet may be reversed multiple times, causing an out-of-bounds write. The vulnerability has been assigned a CVSSv3 score of 8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is classified as CWE-122 (Heap-based Buffer Overflow) (Talos Report).
If successfully exploited, this vulnerability can lead to code execution on the target system when processing a maliciously crafted file (Talos Report).
An attacker can exploit this vulnerability by providing a specially crafted AMF file to the application. The attack requires user interaction to process the malicious file (Talos Report).
The vulnerability was disclosed to the vendor on January 8, 2021, and made public on April 21, 2021. Users should update to a patched version of PrusaSlicer if available (Talos Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."