Ashlar-Vellum Products Heap-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A heap-based buffer overflow vulnerability has been identified in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share, all versions through 12.6.1204.207. This vulnerability could enable an attacker to execute arbitrary code or disclose information.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution or information disclosure.

Remediation

Users are advised to update to versions 12.6.1204.208 or higher. For Cobalt Share, the same version range applies. CISA also recommends minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods such as VPNs.

Added: Nov 25, 2025, 6:17 PM
Updated: Nov 25, 2025, 10:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.9
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.