CVE-2020-13656
Summary
| CVE | CVE-2020-13656 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-12 23:15:00 UTC |
| Updated | 2020-06-22 14:30:00 UTC |
| Description | In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution. |
Risk And Classification
Problem Types: CWE-125 | CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Morganstanley | Hobbes | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OOB to RCE: Exploitation of the Hobbes Functional Interpreter | MISC | know.bishopfox.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Morgan Stanley | 2020-11-09 | [email protected] | The issue outlined in the CVE has been addressed in the latest release of Hobbes as of September 29, 2020. More information on the usage of Hobbes is detailed in the README.md of the project at https://github.com/Morgan-Stanley/hobbes |
There are currently no legacy QID mappings associated with this CVE.