Impact
The flaw resides in the Node Header Handler component of the fbxcel library, affecting file src/pull_parser/v7400/parser.rs. An attacker can craft a malicious input that triggers an unbounded operation, causing the application to hang or crash. The result is a denial-of-service that disrupts normal processing of FBX files, and the weakness corresponds to CWE-404, which describes improper control of a resource.
Affected Systems
This vulnerability applies to lo48576 fbxcel versions up to 0.9.0, run locally on any system that owns or processes FBX files using the library.
Risk and Exploitability
The CVSS score is 4.8, indicating a moderate impact. The EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Because the attack vector is local, an adversary must have access to the host executing the library, but no network exposure is required. The denial of service can terminate processing of media files, potentially affecting downstream services or user workflows.
OpenCVE Enrichment