{"api_version":"1","generated_at":"2026-07-23T09:02:36+00:00","cve":"CVE-2020-13656","urls":{"html":"https://cve.report/CVE-2020-13656","api":"https://cve.report/api/cve/CVE-2020-13656.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-13656","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-13656"},"summary":{"title":"CVE-2020-13656","description":"In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-06-12 23:15:00","updated_at":"2020-06-22 14:30:00"},"problem_types":["CWE-125","CWE-787"],"metrics":[],"references":[{"url":"https://know.bishopfox.com/advisories/oob-to-rce-exploitation-of-the-hobbes-functional-interpreter","name":"https://know.bishopfox.com/advisories/oob-to-rce-exploitation-of-the-hobbes-functional-interpreter","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"OOB to RCE: Exploitation of the Hobbes Functional Interpreter","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-13656","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13656","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"13656","vulnerable":"1","versionEndIncluding":"2020-05-21","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"morganstanley","cpe5":"hobbes","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2020-13656","organization":"Morgan Stanley","lastmodified":"2020-11-09","contributor":"opensource@morganstanley.com","statementText":"The issue outlined in the CVE has been addressed in the latest release of Hobbes as of September 29, 2020. More information on the usage of Hobbes is detailed in the README.md of the project at https://github.com/Morgan-Stanley/hobbes","cve_year":"2020","cve_id":"13656","crc32":"4ad0cab6"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-13656","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://know.bishopfox.com/advisories/oob-to-rce-exploitation-of-the-hobbes-functional-interpreter","url":"https://know.bishopfox.com/advisories/oob-to-rce-exploitation-of-the-hobbes-functional-interpreter"}]}},"nvd":{"publishedDate":"2020-06-12 23:15:00","lastModifiedDate":"2020-06-22 14:30:00","problem_types":["CWE-125","CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:morganstanley:hobbes:*:*:*:*:*:*:*:*","versionEndIncluding":"2020-05-21","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"13656","Ordinal":"174843","Title":"CVE-2020-13656","CVE":"CVE-2020-13656","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"13656","Ordinal":"1","NoteData":"In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"13656","Ordinal":"2","NoteData":"2020-06-12","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"13656","Ordinal":"3","NoteData":"2020-06-12","Type":"Other","Title":"Modified"}]}}}