Impact
Substance3D Designer versions 15.1.0 and earlier are vulnerable to a path traversal flaw that allows an attacker to read arbitrary files on the file system. The weakness enables access to sensitive files and directories outside the intended access scope, which could compromise confidentiality and potentially expose critical data. The issue is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory).
Affected Systems
The affected vendor is Adobe, specifically the Substance3D Designer product. All releases version 15.1.0 and earlier are impacted; newer releases are assumed fixed.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction, meaning a victim must open a malicious file that contains a crafted path. The scope change indicates that the vulnerability can affect system-level resources. With the current exposure, an attacker who can trick a user into opening such a file could read files beyond the application’s intended directory containment, increasing risk to organizational data.
OpenCVE Enrichment