CVE-2020-6977: Input Validation
A restricted desktop environment escape vulnerability exists in the Kiosk Mode functionality of affected devices. Specially crafted inputs can allow the user to escape the restricted environment, resulting in access to the underlying operating system. Affected devices include the following GE Ultrasound Products: Vivid products - all versions; LOGIQ - all versions not including LOGIQ 100 Pro; Voluson - all versions; Versana Essential - all versions; Invenia ABUS Scan station - all versions; Venue - all versions not including Venue 40 R1-3 and Venue 50 R4-5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6977?
CVE-2020-6977 is classified as a medium severity vulnerability due to the potential for unauthorized access to the underlying operating system.
How do I fix CVE-2020-6977?
To fix CVE-2020-6977, update the affected GE Vivid and Logiq firmware to the latest version provided by the manufacturer.
Which devices are affected by CVE-2020-6977?
CVE-2020-6977 affects multiple devices, including GE Vivid E95, Vivid E90, Vivid S70n, Logiq E10, and other specified models.
What type of vulnerability is CVE-2020-6977?
CVE-2020-6977 is a restricted desktop environment escape vulnerability associated with the Kiosk Mode functionality.
What are the potential consequences of CVE-2020-6977?
The potential consequences of CVE-2020-6977 include unauthorized access to the underlying operating system, which can lead to further security risks.