CVE-2022-1741Disclosure(dominionvoting / democracy_suite)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or install malicious code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • democracy_suite
  • imagecast_x

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
democracy_suiteimagecast_x

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-25: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-25: 103-1903-25
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-251
General1
Full discourse2 posts
  • ChinMusic 🇺🇸 ⚾️@RealChinMusic
    Disclosure

    CISA report on vulnerabilities: Improper crypto signature check (CVE-2022-1739): Lets fake apps install. • Mutable self-attestation (CVE-2022-1740): Hides malware in logs or hashes. • Hidden terminal emulator (CVE-2022-1741): Backdoor for root access. • Safe mode reboot trick (CVE-2022-1742): Drops into Android OS for full control. • Path traversal in files (CVE-2022-1743): Zip tricks execute code from election defs. • Unnecessary privileges (CVE-2022-1744): Apps run too high, easy escalation. • Technician card spoofing (CVE-2022-1745): Fake cards get admin rights. • Poll worker auth leak (CVE-2022-1746): Exposes keys for other machines. • Voter session forgery (CVE-2022-1747): Print unlimited ballots.

    Post summary

    The text presents a CISA vulnerability report listing multiple CVEs with brief descriptions of their potential impact, serving as an initial disclosure of the security issues.

    17090565
    6.2K followersView on X
  • ChinMusic 🇺🇸 ⚾️@RealChinMusic
    General

    CISA's list of Dominion vulnerabilities: CVE-2022-1739: Improper verification of cryptographic signature (allows malicious code via removable media) CVE-2022-1740: Mutable attestation/measurement reporting data (disguise malicious apps) CVE-2022-1741: Hidden functionality (terminal emulator for privilege escalation) CVE-2022-1742: Improper protection of alternate path (Android Safe Mode access) CVE-2022-1743: Path traversal ('../filedir') in election definition files (arbitrary code execution) CVE-2022-1744: Execution with unnecessary privileges (elevated code execution) CVE-2022-1745: Authentication bypass by spoofing (technician auth forgery) CVE-2022-1746: Incorrect privilege assignment (poll worker exposes crypto secrets) CVE-2022-1747: Origin validation error (voter session forgery for ballot printing)

    Post summary

    The text enumerates seven CISA-documented Dominion vulnerabilities, providing brief technical descriptions for each but lacking evidence of exploitation, PoC, or remediation steps.

    0001043
    6.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWdominionvotingdemocracy_suite5.5-a--
OSdominionvotingimagecast_x---
Appdominionvotingimagecast_x5.5.10.30--
Appdominionvotingimagecast_x5.5.10.32--

Explore more