#VU63992 Hidden functionality in ImageCast X


Published: 2022-06-06

Vulnerability identifier: #VU63992

Vulnerability risk: Low

CVSSv3.1: 6.1 [CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2022-1741

CWE-ID: CWE-912

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
ImageCast X
Hardware solutions / Other hardware appliances

Vendor: Dominion Voting Systems

Description

The vulnerability allows a local user to compromise vulnerable system

The vulnerability exists due to hidden functionality (backdoor) is present in software within the Terminal Emulator application. An authenticated attacker with physical access can use this functionality to gain elevated privileges on the device and install malicious code.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

ImageCast X: 5.5.10.30 - 5.5.10.32


External links
http://ics-cert.us-cert.gov/advisories/icsa-22-154-01


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability