CVE-2024-1628: Ge Healthcare Invenia Abus 2.0
High severity, CVSS 8.4. EPSS: 0.8% chance of exploitation in the next 30 days.
OS command injection vulnerabilities in GE HealthCare ultrasound devices
Affected products
- Ge Healthcare Invenia Abus 2.0: up to and including 2.2.7
- Ge Healthcare Logiq
- Ge Healthcare Logiq E: from R7, up to and including R9.1.4; from R8, up to and including R10.1.3; from R9, up to and including R11.0.3
- Ge Healthcare Logiq e10: before R3.2.0 (fixed in R3.2.0)
- Ge Healthcare Logiq e10s: before R3.2.0 (fixed in R3.2.0)
- Ge Healthcare Logiq Fortis: before R3.2.0 (fixed in R3.2.0)
- Ge Healthcare Logiq He: up to and including R9.3.1
- Ge Healthcare Venue: version R1 only; version R2 only; from R3, up to and including R3.3; from R4, up to and including R4.3
- Ge Healthcare Venue Fit: from R3, up to and including R3.3; from R4, up to and including R4.3
- Ge Healthcare Venue Go: version R2 only; from R3, up to and including R3.3; from R4, up to and including R4.3
- Ge Healthcare Vivid
- Ge Healthcare Vivid E: from E95, before 206 (fixed in 206); from E90, before 206 (fixed in 206); from E80, before 206 (fixed in 206)
- Ge Healthcare Vivid Iq: before 206 (fixed in 206)
- Ge Healthcare Vivid S: from 70N, before 206 (fixed in 206); from 60N, before 206 (fixed in 206)
- Ge Healthcare Vivid T: from T8, before 206 (fixed in 206); from T9, before 206 (fixed in 206)
- Ge Healthcare Voluson
- Ge Healthcare Voluson Expert 16: version 0 only
- Ge Healthcare Voluson Expert 18: version 0 only
- Ge Healthcare Voluson Expert 22: version 0 only
- Ge Healthcare Voluson Swift: version 0 only
Published 2024-05-14. Last modified 2026-06-17.