CVE-2023-40222

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsing CO files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*

History

16 Sep 2025, 16:54

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-299-03 - Third Party Advisory, US Government Resource
First Time Ashlar
Ashlar cobalt
Summary
  • (es) En las versiones de Ashlar-Vellum Cobalt anteriores a v12 SP2 Build (1204.200), la aplicación afectada carece de una validación adecuada de los datos proporcionados por el usuario al analizar archivos CO. Esto podría provocar un desbordamiento del búfer basado en el montón. Un atacante podría aprovechar esta vulnerabilidad para ejecutar código arbitrario en el contexto del proceso actual.
CPE cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*

04 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-04 23:15

Updated : 2025-09-16 16:54


NVD link : CVE-2023-40222

Mitre link : CVE-2023-40222

CVE.ORG link : CVE-2023-40222


JSON object : View

Products Affected

ashlar

  • cobalt
CWE
CWE-122

Heap-based Buffer Overflow