CVE-2020-24753 is a critical memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) versions prior to 2020-08-12. An attacker can exploit this by providing crafted CBOR input to the cbor2json decoder, leading to an uncaught error during text string decoding that uses an uninitialized stack value. This allows for memory modification, potentially causing a crash or exploitable heap corruption. Rated with a CVSS score of 9.8 (CRITICAL), this vulnerability has a low attack complexity and requires no user interaction or privileges, making it easily exploitable over a network. Successful exploitation could lead to complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is currently no evidence of active exploitation, nor are there public exploit modules available in common frameworks like Metasploit or Nuclei. Community discussion and media coverage for this CVE are minimal, consistent with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020-08-12CPE matchmatch criteria | cpe:2.3:a:objective_open_cbor_run-time_project:objective_open_cbor_run-time:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.