CVE-2022-1743Disclosure(dominionvoting / democracy_suite)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by specially crafted election definition files. An attacker could leverage this vulnerability to spread malicious code to ImageCast X devices from the EMS.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • democracy_suite
  • imagecast_x

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
democracy_suiteimagecast_x

3 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-13: 1Mentions · 2026-03-19: 1Mentions · 2026-03-25: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-25: 102-1303-1903-25
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-131
General1
2026-03-191
Disclosure1
2026-03-251
Disclosure1
Full discourse3 posts
  • ChinMusic 🇺🇸 ⚾️@RealChinMusic
    Disclosure

    CISA report on vulnerabilities: Improper crypto signature check (CVE-2022-1739): Lets fake apps install. • Mutable self-attestation (CVE-2022-1740): Hides malware in logs or hashes. • Hidden terminal emulator (CVE-2022-1741): Backdoor for root access. • Safe mode reboot trick (CVE-2022-1742): Drops into Android OS for full control. • Path traversal in files (CVE-2022-1743): Zip tricks execute code from election defs. • Unnecessary privileges (CVE-2022-1744): Apps run too high, easy escalation. • Technician card spoofing (CVE-2022-1745): Fake cards get admin rights. • Poll worker auth leak (CVE-2022-1746): Exposes keys for other machines. • Voter session forgery (CVE-2022-1747): Print unlimited ballots.

    Post summary

    CISA publishes a list of Android OS CVEs with concise vulnerability descriptions, but provides no exploit code, PoC, patch announcement, or evidence of active exploitation.

    17090565
    6.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2022-1743 2 - CVE-2026-20841 3 - CVE-2025-15556 4 - CVE-2026-25253 5 - CVE-2026-1731 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVE identifiers without providing any additional technical detail, mitigation, or evidence of exploitation.

    01020197
    1.7K followersView on X
  • ChinMusic 🇺🇸 ⚾️@RealChinMusic
    Disclosure

    CISA's list of Dominion vulnerabilities: CVE-2022-1739: Improper verification of cryptographic signature (allows malicious code via removable media) CVE-2022-1740: Mutable attestation/measurement reporting data (disguise malicious apps) CVE-2022-1741: Hidden functionality (terminal emulator for privilege escalation) CVE-2022-1742: Improper protection of alternate path (Android Safe Mode access) CVE-2022-1743: Path traversal ('../filedir') in election definition files (arbitrary code execution) CVE-2022-1744: Execution with unnecessary privileges (elevated code execution) CVE-2022-1745: Authentication bypass by spoofing (technician auth forgery) CVE-2022-1746: Incorrect privilege assignment (poll worker exposes crypto secrets) CVE-2022-1747: Origin validation error (voter session forgery for ballot printing)

    Post summary

    The text lists several CVEs disclosed by CISA with brief technical details, but no PoC, exploit code, active exploitation, or patch information.

    0001043
    6.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWdominionvotingdemocracy_suite5.5-a--
OSdominionvotingimagecast_x---
Appdominionvotingimagecast_x5.5.10.30--
Appdominionvotingimagecast_x5.5.10.32--

Explore more