Ashlar-Vellum Products Out-of-Bounds Write Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing out-of-bounds write operations has been identified in multiple Ashlar-Vellum products, including Cobalt, Xenon, Argon, Lithium, and Cobalt Share, all versions through 12.6.1204.207. This vulnerability could enable an attacker to execute arbitrary code or disclose information.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure or arbitrary code execution.

Remediation

Users are advised to update to Ashlar-Vellum versions 12.6.1204.208 or higher. CISA recommends minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods such as VPNs.

Added: Nov 25, 2025, 6:18 PM
Updated: Nov 25, 2025, 10:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.9
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.