A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5

Project Subscriptions

Vendors Products
Invenia Abus Scan Station Subscribe
Invenia Abus Scan Station Firmware Subscribe
Logiq E10 Subscribe
Logiq E10 Firmware Subscribe
Logiq E9 Subscribe
Logiq E9 Firmware Subscribe
Logiq E9 With Xdclear Subscribe
Logiq E9 With Xdclear Firmware Subscribe
Logiq P9 Subscribe
Logiq P9 Firmware Subscribe
Logiq S7 Subscribe
Logiq S7 Firmware Subscribe
Logiq S8 Subscribe
Logiq S8 Firmware Subscribe
Venue Go Subscribe
Venue Go Firmware Subscribe
Versana Essential Subscribe
Versana Essential Firmware Subscribe
Vivid E90 Subscribe
Vivid E90 Firmware Subscribe
Vivid E95 Subscribe
Vivid E95 Firmware Subscribe
Vivid Iq Subscribe
Vivid Iq Firmware Subscribe
Vivid S70n Subscribe
Vivid S70n Firmware Subscribe
Vivid T8 Subscribe
Vivid T8 Firmware Subscribe
Vivid T9 Subscribe
Vivid T9 Firmware Subscribe
Voluson Subscribe
Voluson Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-28117 A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T09:18:03.015Z

Reserved: 2020-01-14T00:00:00

Link: CVE-2020-6977

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-20T21:15:11.787

Modified: 2024-11-21T05:36:25.253

Link: CVE-2020-6977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.