Protection Mechanism Failure in GE products - CVE-2020-6977

 

Protection Mechanism Failure in GE products - CVE-2020-6977

Published: February 19, 2020


Vulnerability identifier: #VU25442
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-6977
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: GE
Affected software:
Vivid products
LOGIQ
Voluson
Versana Essential
Invenia ABUS Scan station
Venue

Detailed vulnerability description

The vulnerability allows a local attacker to gain access to the operating system of affected devices.

The vulnerability exists due to a restricted desktop environment escape in the "Kiosk Mode" functionality. An attacker with physical access can use specially crafted inputs and escape the restricted environment, resulting in access to the underlying operating system.

Note: This vulnerability does not affect LOGIQ 100 Pro, Venue 40 R1-3 and Venue 50 R4-5.


How to mitigate CVE-2020-6977

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Sources