PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-65085 Ashlar-Vellum CVE debrief

A heap-based buffer overflow vulnerability exists in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior. The vulnerability could allow an attacker to disclose information or execute arbitrary code. The vendor has released an updated build (12.6.1204.217) to address this issue. This vulnerability was initially published on November 25, 2025, and subsequently updated on May 12, 2026, with revised mitigation guidance and affected product versions.

Vendor
Ashlar-Vellum
Product
Cobalt
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-11-25
Original CVE updated
2026-05-12
Advisory published
2025-11-25
Advisory updated
2026-05-12

Who should care

Organizations using Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share in design, engineering, or manufacturing workflows. Industrial control system operators where these applications interface with OT environments. Security teams responsible for CAD/CAM software asset management.

Technical summary

The vulnerability is a heap-based buffer overflow (CWE-122) affecting multiple Ashlar-Vellum CAD and 3D modeling products. Successful exploitation could result in information disclosure or arbitrary code execution. The attack vector is local, requiring user interaction. The CVSS 3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating high impacts to confidentiality, integrity, and availability. The vendor has provided a patched build (12.6.1204.217) as remediation.

Defensive priority

HIGH

Recommended defensive actions

  • Update Ashlar-Vellum products to build 12.6.1204.217 or later as recommended by the vendor.
  • Apply defense-in-depth strategies for industrial control systems environments where these products are deployed.
  • Follow CISA recommended practices for ICS security and implement network segmentation to limit exposure.
  • Educate users on phishing and social engineering risks to reduce initial access vectors.

Evidence notes

Source: CISA CSAF advisory ICSA-25-329-01. Vendor confirmed affected products and remediation. CVSS 3.1 score 7.8 (HIGH). CWE-122 (Heap-based Buffer Overflow).

Sources and references

Verified primary and authoritative sources

  • CVE-2025-65085 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-65085

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-65085 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-65085

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-329-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.