CVE-2023-39943

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*

History

16 Sep 2025, 16:59

Type Values Removed Values Added
First Time Ashlar
Ashlar cobalt
Summary
  • (es) En las versiones de Ashlar-Vellum Cobalt anteriores a v12 SP2 Build (1204.200), la aplicación afectada carece de una validación adecuada de los datos proporcionados por el usuario al analizar archivos XE. Esto podría provocar una escritura fuera de los límites. Un atacante podría aprovechar esta vulnerabilidad para ejecutar código arbitrario en el contexto del proceso actual.
CPE cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03 - Third Party Advisory, US Government Resource

04 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-04 23:15

Updated : 2025-09-16 16:59


NVD link : CVE-2023-39943

Mitre link : CVE-2023-39943

CVE.ORG link : CVE-2023-39943


JSON object : View

Products Affected

ashlar

  • cobalt
CWE
CWE-787

Out-of-bounds Write