CVE-2020-6977
Summary
| CVE | CVE-2020-6977 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-20 21:15:00 UTC |
| Updated | 2020-03-05 15:08:00 UTC |
| Description | A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5 |
Risk And Classification
Problem Types: CWE-20 | NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ge | Invenia Abus Scan Station | - | All | All | All |
| Hardware | Ge | Invenia Abus Scan Station | - | All | All | All |
| Operating System | Ge | Invenia Abus Scan Station Firmware | All | All | All | All |
| Operating System | Ge | Invenia Abus Scan Station Firmware | All | All | All | All |
| Hardware | Ge | Logiq E10 | - | All | All | All |
| Hardware | Ge | Logiq E10 | - | All | All | All |
| Operating System | Ge | Logiq E10 Firmware | All | All | All | All |
| Operating System | Ge | Logiq E10 Firmware | All | All | All | All |
| Hardware | Ge | Logiq E9 | - | All | All | All |
| Hardware | Ge | Logiq E9 | - | All | All | All |
| Operating System | Ge | Logiq E9 Firmware | All | All | All | All |
| Operating System | Ge | Logiq E9 Firmware | All | All | All | All |
| Hardware | Ge | Logiq E9 With Xdclear | - | All | All | All |
| Hardware | Ge | Logiq E9 With Xdclear | - | All | All | All |
| Operating System | Ge | Logiq E9 With Xdclear Firmware | All | All | All | All |
| Operating System | Ge | Logiq E9 With Xdclear Firmware | All | All | All | All |
| Hardware | Ge | Logiq P9 | - | All | All | All |
| Hardware | Ge | Logiq P9 | - | All | All | All |
| Operating System | Ge | Logiq P9 Firmware | All | All | All | All |
| Operating System | Ge | Logiq P9 Firmware | All | All | All | All |
| Hardware | Ge | Logiq S7 | - | All | All | All |
| Hardware | Ge | Logiq S7 | - | All | All | All |
| Operating System | Ge | Logiq S7 Firmware | All | All | All | All |
| Operating System | Ge | Logiq S7 Firmware | All | All | All | All |
| Hardware | Ge | Logiq S8 | - | All | All | All |
| Hardware | Ge | Logiq S8 | - | All | All | All |
| Operating System | Ge | Logiq S8 Firmware | All | All | All | All |
| Operating System | Ge | Logiq S8 Firmware | All | All | All | All |
| Hardware | Ge | Venue Go | - | All | All | All |
| Hardware | Ge | Venue Go | - | All | All | All |
| Operating System | Ge | Venue Go Firmware | All | All | All | All |
| Operating System | Ge | Venue Go Firmware | All | All | All | All |
| Hardware | Ge | Versana Essential | - | All | All | All |
| Hardware | Ge | Versana Essential | - | All | All | All |
| Operating System | Ge | Versana Essential Firmware | All | All | All | All |
| Operating System | Ge | Versana Essential Firmware | All | All | All | All |
| Hardware | Ge | Vivid E90 | - | All | All | All |
| Hardware | Ge | Vivid E90 | - | All | All | All |
| Operating System | Ge | Vivid E90 Firmware | All | All | All | All |
| Operating System | Ge | Vivid E90 Firmware | All | All | All | All |
| Hardware | Ge | Vivid E95 | - | All | All | All |
| Hardware | Ge | Vivid E95 | - | All | All | All |
| Operating System | Ge | Vivid E95 Firmware | All | All | All | All |
| Operating System | Ge | Vivid E95 Firmware | All | All | All | All |
| Hardware | Ge | Vivid Iq | - | All | All | All |
| Hardware | Ge | Vivid Iq | - | All | All | All |
| Operating System | Ge | Vivid Iq Firmware | All | All | All | All |
| Operating System | Ge | Vivid Iq Firmware | All | All | All | All |
| Hardware | Ge | Vivid S70n | - | All | All | All |
| Hardware | Ge | Vivid S70n | - | All | All | All |
| Operating System | Ge | Vivid S70n Firmware | All | All | All | All |
| Operating System | Ge | Vivid S70n Firmware | All | All | All | All |
| Hardware | Ge | Vivid T8 | - | All | All | All |
| Hardware | Ge | Vivid T8 | - | All | All | All |
| Operating System | Ge | Vivid T8 Firmware | All | All | All | All |
| Operating System | Ge | Vivid T8 Firmware | All | All | All | All |
| Hardware | Ge | Vivid T9 | - | All | All | All |
| Hardware | Ge | Vivid T9 | - | All | All | All |
| Operating System | Ge | Vivid T9 Firmware | All | All | All | All |
| Operating System | Ge | Vivid T9 Firmware | All | All | All | All |
| Hardware | Ge | Voluson | - | All | All | All |
| Hardware | Ge | Voluson | - | All | All | All |
| Operating System | Ge | Voluson Firmware | All | All | All | All |
| Operating System | Ge | Voluson Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GE Ultrasound products | CISA | MISC | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.