← Back

CVE-2022-1739

nvd nist
Published: Jun 24, 2022Modified: Apr 17, 2025

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software installed on a device is traceable to, or verifiable against, a cryptographic key provided by the manufacturer to detect tampering. An attacker could leverage this vulnerability to install malicious code, which could also be spread to other vulnerable ImageCast X devices via removable media.

Affected (3)

Imagecast X
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dominionvoting
Version 5.5.10.30
Version 5.5.10.32
Running on/withPlatform Versions
Dominionvoting
Democracy Suite
Version 5.5-a

References (2)

Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.