Vulnerabilities Affecting Dominion Voting Systems ImageCast X
Multiple vulnerabilities in Dominion ImageCast X voting devices (CWE-347, CWE-1283, CWE-912, CWE-424, CWE-24, CWE-250, CWE-290, CWE-266, CWE-346) allow arbitrary code execution. These affect the ImageCast X firmware running on Android 5.1 and the ImageCast X application (versions 5.5.10.30 and 5.5.10.32) used in Dominion Democracy Suite voting systems. Exploitation requires physical access to the device and could allow an attacker to manipulate ballot data, vote tallies, or audit logs. The vulnerabilities span improper cryptographic signature verification, insecure direct object references, insufficient input validation, and improper access controls.
- Physical access to ImageCast X device
- No authentication required to exploit the firmware/application vulnerabilities
Patching may require device reboot — plan for process interruption
/api/v1/advisories/5fbd29d8-2458-41e6-9b1e-a0586aba85b2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.