7.2

CVE-2020-6977

A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ge ≫ Vivid E95 Firmware
   Ge ≫ Vivid E95 Version -
Ge ≫ Vivid E90 Firmware
   Ge ≫ Vivid E90 Version -
Ge ≫ Vivid S70n Firmware
   Ge ≫ Vivid S70n Version -
Ge ≫ Vivid T8 Firmware
   Ge ≫ Vivid T8 Version -
Ge ≫ Vivid T9 Firmware
   Ge ≫ Vivid T9 Version -
Ge ≫ Vivid Iq Firmware
   Ge ≫ Vivid Iq Version -
Ge ≫ Logiq E10 Firmware
   Ge ≫ Logiq E10 Version -
Ge ≫ Logiq E9 Firmware
   Ge ≫ Logiq E9 Version -
Ge ≫ Logiq S8 Firmware
   Ge ≫ Logiq S8 Version -
Ge ≫ Logiq S7 Firmware
   Ge ≫ Logiq S7 Version -
Ge ≫ Logiq P9 Firmware
   Ge ≫ Logiq P9 Version -
Ge ≫ Voluson Firmware
   Ge ≫ Voluson Version -
Ge ≫ Venue Go Firmware
   Ge ≫ Venue Go Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.34
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-693 Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

https://www.us-cert.gov/ics/advisories/icsma-20-049-02
Third Party Advisory
US Government Resource