← Back to home
ICSA-23-299-03  ·  Published 2025-02-04  ·  View on CISA ICS-CERT ↗

Ashlar-Vellum Cobalt, Graphite, Xenon, Argon, Lithium (Update A)

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code.

Remediations

  • Ashlar-Vellum recommends users apply the following mitigations to help reduce risk:
  • Install the latest version of Graphite.
  • Update to the latest version for Cobalt, Xenon, Lithium, and Argon by installing v12 SP12 Alpha Build (1204.200) (Jan 22, 2025).
  • Only open files from trusted sources.

Affected Vendors

Ashlar-Vellum

Affected Products (6)

Ashlar-Vellum · Cobalt <v12_SP2_Build_1204.200
Ashlar-Vellum · Cobalt Share <v12_SP2_Build_1204.200
Ashlar-Vellum · Graphite <=v13.0.48
Ashlar-Vellum · Xenon <v12_SP2_Build_1204.200
Ashlar-Vellum · Argon <v12_SP2_Build_1204.200
Ashlar-Vellum · Lithium <v12_SP2_Build_1204.200

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more