#VU63997 Incorrect Privilege Assignment in ImageCast X


Published: 2022-06-06

Vulnerability identifier: #VU63997

Vulnerability risk: Low

CVSSv3.1: 6.1 [CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C]

CVE-ID: CVE-2022-1746

CWE-ID: CWE-266

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
ImageCast X
Hardware solutions / Other hardware appliances

Vendor: Dominion Voting Systems

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to the authentication mechanism used by poll workers to administer voting can expose cryptographic secrets used to protect election information. An authenticated attacker with physical access can gain access to sensitive information and perform privileged actions.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

ImageCast X: 5.5.10.30 - 5.5.10.32


External links
http://ics-cert.us-cert.gov/advisories/icsa-22-154-01


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability