Protection Mechanism Failure in GE products - CVE-2020-6977
Published: February 19, 2020
Vivid products
LOGIQ
Voluson
Versana Essential
Invenia ABUS Scan station
Venue
Detailed vulnerability description
The vulnerability allows a local attacker to gain access to the operating system of affected devices.
The vulnerability exists due to a restricted desktop environment escape in the "Kiosk Mode" functionality. An attacker with physical access can use specially crafted inputs and escape the restricted environment, resulting in access to the underlying operating system.
Note: This vulnerability does not affect LOGIQ 100 Pro, Venue 40 R1-3 and Venue 50 R4-5.