CVE-2025-2013
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 78
Summary
CVE-2025-2013 is a remote code execution vulnerability affecting Ashlar-Vellum Cobalt software. This issue stems from the lack of validation when parsing CO files, leading to a use-after-free condition. An attacker can exploit this vulnerability by crafting a malicious CO file or luring a user to a malicious webpage. Successful exploitation grants the attacker the ability to execute arbitrary code in the context of the current process.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco IOS
Affected Vendors
- Cisco