VendorsDominionvotingdemocracy_suite5.5-a
Vulnerabilities

Dominionvoting Democracy Suite 5.5-a

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-1746
2.2.8 INCORRECT PRIVILEGE ASSIGNMENT CWE-266
Published 2022-06-24 · Modified
7.6EPSS 0.003
CVE-2022-1743
2.2.5 PATH TRAVERSAL: '../FILEDIR' CWE-24
Published 2022-06-24 · Modified
7.2EPSS 0.004
CVE-2022-1744
2.2.6 EXECUTION WITH UNNECESSARY PRIVILEGES CWE-250
Published 2022-06-24 · Modified
7.2EPSS 0.003
CVE-2022-1745
2.2.7 AUTHENTICATION BYPASS BY SPOOFING CWE-290
Published 2022-06-24 · Modified
7.2EPSS 0.003
CVE-2022-1741
2.2.3 HIDDEN FUNCTIONALITY CWE-912
Published 2022-06-24 · Modified
7.2EPSS 0.003
CVE-2022-1742
2.2.4 IMPROPER PROTECTION OF ALTERNATE PATH CWE-424
Published 2022-06-24 · Modified
7.2EPSS 0.003
CVE-2022-1739
2.2.1 IMPROPER VERIFICATION OF CRYPTOGRAPHIC SIGNATURE CWE-347
Published 2022-06-24 · Modified
7.2EPSS 0.001
CVE-2022-1740
2.2.2 MUTABLE ATTESTATION OR MEASUREMENT REPORTING DATA CWE-1283
Published 2022-06-24 · Modified
4.6EPSS 0.002
CVE-2022-1747
The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker could leverage this vulnerability to print an arbitrary number of ballots without authorization.
Published 2022-06-24 · Modified
4.6EPSS 0.002
CVE-2022-48506
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in which ballots were cast from public ballot-level data, allowing deanonymization of voted ballots, in several types of scenarios. This issue was observed for use of the following versions of Democracy Suite: 5.2, 5.4-NM, 5.5, 5.5-A, 5.5-B, 5.5-C, 5.5-D, 5.7-A, 5.10, 5.10A, 5.15. NOTE: the Democracy Suite 5.17 EAC Certificate of Conformance mentions "Improved pseudo random number algorithm," which may be relevant.
Published 2023-06-19 · Modified
2.4EPSS 0.004