6.8
CVSSv3

CVE-2020-6977

Published: 20/02/2020 Updated: 05/03/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ge vivid_e95_firmware

ge vivid_e90_firmware

ge vivid_s70n_firmware

ge vivid_t8_firmware

ge vivid_t9_firmware

ge vivid_iq_firmware

ge logiq_e10_firmware

ge logiq_e9_firmware

ge logiq_s8_firmware

ge logiq_s7_firmware

ge logiq_p9_firmware

ge logiq_e9_with_xdclear_firmware

ge voluson_firmware

ge versana_essential_firmware

ge invenia_abus_scan_station_firmware

ge venue_go_firmware