CVE-2024-1628: Ge Healthcare Invenia Abus 2.0

High severity, CVSS 8.4. EPSS: 0.8% chance of exploitation in the next 30 days.

OS command injection vulnerabilities in GE HealthCare ultrasound devices

Affected products

  • Ge Healthcare Invenia Abus 2.0: up to and including 2.2.7
  • Ge Healthcare Logiq
  • Ge Healthcare Logiq E: from R7, up to and including R9.1.4; from R8, up to and including R10.1.3; from R9, up to and including R11.0.3
  • Ge Healthcare Logiq e10: before R3.2.0 (fixed in R3.2.0)
  • Ge Healthcare Logiq e10s: before R3.2.0 (fixed in R3.2.0)
  • Ge Healthcare Logiq Fortis: before R3.2.0 (fixed in R3.2.0)
  • Ge Healthcare Logiq He: up to and including R9.3.1
  • Ge Healthcare Venue: version R1 only; version R2 only; from R3, up to and including R3.3; from R4, up to and including R4.3
  • Ge Healthcare Venue Fit: from R3, up to and including R3.3; from R4, up to and including R4.3
  • Ge Healthcare Venue Go: version R2 only; from R3, up to and including R3.3; from R4, up to and including R4.3
  • Ge Healthcare Vivid
  • Ge Healthcare Vivid E: from E95, before 206 (fixed in 206); from E90, before 206 (fixed in 206); from E80, before 206 (fixed in 206)
  • Ge Healthcare Vivid Iq: before 206 (fixed in 206)
  • Ge Healthcare Vivid S: from 70N, before 206 (fixed in 206); from 60N, before 206 (fixed in 206)
  • Ge Healthcare Vivid T: from T8, before 206 (fixed in 206); from T9, before 206 (fixed in 206)
  • Ge Healthcare Voluson
  • Ge Healthcare Voluson Expert 16: version 0 only
  • Ge Healthcare Voluson Expert 18: version 0 only
  • Ge Healthcare Voluson Expert 22: version 0 only
  • Ge Healthcare Voluson Swift: version 0 only

Published 2024-05-14. Last modified 2026-06-17.