A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5
Project Subscriptions
| Vendors | Products |
|---|---|
|
Ge
Subscribe
|
Invenia Abus Scan Station
Subscribe
Invenia Abus Scan Station Firmware
Subscribe
Logiq E10
Subscribe
Logiq E10 Firmware
Subscribe
Logiq E9
Subscribe
Logiq E9 Firmware
Subscribe
Logiq E9 With Xdclear
Subscribe
Logiq E9 With Xdclear Firmware
Subscribe
Logiq P9
Subscribe
Logiq P9 Firmware
Subscribe
Logiq S7
Subscribe
Logiq S7 Firmware
Subscribe
Logiq S8
Subscribe
Logiq S8 Firmware
Subscribe
Venue Go
Subscribe
Venue Go Firmware
Subscribe
Versana Essential
Subscribe
Versana Essential Firmware
Subscribe
Vivid E90
Subscribe
Vivid E90 Firmware
Subscribe
Vivid E95
Subscribe
Vivid E95 Firmware
Subscribe
Vivid Iq
Subscribe
Vivid Iq Firmware
Subscribe
Vivid S70n
Subscribe
Vivid S70n Firmware
Subscribe
Vivid T8
Subscribe
Vivid T8 Firmware
Subscribe
Vivid T9
Subscribe
Vivid T9 Firmware
Subscribe
Voluson
Subscribe
Voluson Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28117 | A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsma-20-049-02 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T09:18:03.015Z
Reserved: 2020-01-14T00:00:00
Link: CVE-2020-6977
No data.
Status : Modified
Published: 2020-02-20T21:15:11.787
Modified: 2024-11-21T05:36:25.253
Link: CVE-2020-6977
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD