PT-2020-6969 · Ge Healthcare · Vivid+6

Published

2020-02-18

·

Updated

2024-05-17

·

CVE-2020-6977

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GE HealthCare Ultrasound Products versions all versions Vivid products versions all versions LOGIQ versions all versions, excluding LOGIQ 100 Pro Voluson versions all versions Versana Essential versions all versions Invenia ABUS Scan station versions all versions Venue versions all versions, excluding Venue 40 R1-3 and Venue 50 R4-5
Description The issue is related to a security mechanism bypass in the Kiosk Mode of GE HealthCare ultrasound systems, allowing an attacker to bypass security restrictions, gain unauthorized access to protected information, and elevate their privileges. A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality, enabling a user to escape the restricted environment with specially crafted inputs and access the underlying operating system.
Recommendations For Vivid products, restrict access to the Kiosk Mode functionality until a patch is available. For LOGIQ, excluding LOGIQ 100 Pro, consider disabling the Kiosk Mode feature to minimize the risk of exploitation. For Voluson, Versana Essential, and Invenia ABUS Scan station, avoid using the Kiosk Mode until the issue is resolved. For Venue, excluding Venue 40 R1-3 and Venue 50 R4-5, temporarily disable the Kiosk Mode to prevent potential attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-04475
CVE-2020-6977

Affected Products

Ge Healthcare Ultrasound Products
Invenia Abus Scan Station
Logiq
Venue
Versana Essential
Vivid
Voluson