Saturday, June 4, 2022

Vulnerabilities Affecting Dominion Voting Systems ImageCast X

SUMMARY. This advisory identifies vulnerabilities affecting versions of the Dominion Voting Systems Democracy Suite ImageCast X, which is an in-person voting system used to allow voters to mark their ballot.

While these vulnerabilities present risks that should be mitigated as soon as possible, CISA has no evidence that these vulnerabilities have been exploited in any elections.

Exploitation of these vulnerabilities would require physical access to individual ImageCast X devices, access to the Election Management System, or the ability to modify files before they are uploaded to ImageCast X devices.

Jurisdictions can prevent and/or detect the exploitation of these vulnerabilities by diligently applying the mitigations recommended in this advisory, including technical, physical, and operational controls that limit unauthorized access or manipulation of voting systems.

Any jurisdictions running ImageCast X are encouraged to contact Dominion Voting Systems to understand the vulnerability status of their specific implementation.

An attacker could leverage this vulnerability to spread malicious code to ImageCast X devices from the EMS. CVE-2022-1743 has been assigned to this vulnerability.

Dominion Voting Systems reports to CISA that the above vulnerabilities have been addressed in subsequent software versions.

https://www.cisa.gov/uscert/ics/advisories/icsa-22-154-01 

No comments: