CVE-2022-1742General(dominionvoting / democracy_suite)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an attacker to directly access the operating system. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-424

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • democracy_suite
  • imagecast_x

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
democracy_suiteimagecast_x

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-25: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-25: 103-1903-25
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Classification over time
DateTotalLabels
2026-03-191
General1
2026-03-251
Disclosure1
Full discourse2 posts
  • ChinMusic 🇺🇸 ⚾️@RealChinMusic
    General

    CISA report on vulnerabilities: Improper crypto signature check (CVE-2022-1739): Lets fake apps install. • Mutable self-attestation (CVE-2022-1740): Hides malware in logs or hashes. • Hidden terminal emulator (CVE-2022-1741): Backdoor for root access. • Safe mode reboot trick (CVE-2022-1742): Drops into Android OS for full control. • Path traversal in files (CVE-2022-1743): Zip tricks execute code from election defs. • Unnecessary privileges (CVE-2022-1744): Apps run too high, easy escalation. • Technician card spoofing (CVE-2022-1745): Fake cards get admin rights. • Poll worker auth leak (CVE-2022-1746): Exposes keys for other machines. • Voter session forgery (CVE-2022-1747): Print unlimited ballots.

    Post summary

    CISA provides a succinct list of several Android CVEs with brief exploit descriptions, but offers no PoC, patch, or evidence of active exploitation.

    17090565
    6.2K followersView on X
  • ChinMusic 🇺🇸 ⚾️@RealChinMusic
    Disclosure

    CISA's list of Dominion vulnerabilities: CVE-2022-1739: Improper verification of cryptographic signature (allows malicious code via removable media) CVE-2022-1740: Mutable attestation/measurement reporting data (disguise malicious apps) CVE-2022-1741: Hidden functionality (terminal emulator for privilege escalation) CVE-2022-1742: Improper protection of alternate path (Android Safe Mode access) CVE-2022-1743: Path traversal ('../filedir') in election definition files (arbitrary code execution) CVE-2022-1744: Execution with unnecessary privileges (elevated code execution) CVE-2022-1745: Authentication bypass by spoofing (technician auth forgery) CVE-2022-1746: Incorrect privilege assignment (poll worker exposes crypto secrets) CVE-2022-1747: Origin validation error (voter session forgery for ballot printing)

    Post summary

    The passage lists several CVE identifiers from CISA's Dominion vulnerabilities, each with a brief technical description; no POV, exploit, active use, or patch information is provided.

    0001043
    6.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWdominionvotingdemocracy_suite5.5-a--
OSdominionvotingimagecast_x---
Appdominionvotingimagecast_x5.5.10.30--
Appdominionvotingimagecast_x5.5.10.32--

Explore more