Dominionvoting develops election management and voting equipment, including the Democracy Suite and ImageCast X systems, which are among the more prominent vendors tracked in the vulnerability landscape given the critical infrastructure role of voting systems. Its disclosed vulnerabilities recur around authentication bypass through spoofing, execution with unnecessary privileges, hidden functionality, and improper protection of alternate code paths—weakness classes that reflect both the authentication and access-control demands of systems designed to prevent unauthorized modification of election data. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dominionvoting over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-1743MEDIUM The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by specially crafted election definition files. An attacker could leve | Jun 24, 2022 | 6.8 | 24 | NO | NO |
CVE-2022-1744MEDIUM Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by exploiting a system level service. An attacker could leverage | Jun 24, 2022 | 6.8 | 23 | NO | NO |
CVE-2022-1742MEDIUM The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an attacker to directly access the operating system. An attacker | Jun 24, 2022 | 6.8 | 23 | NO | NO |
CVE-2022-1741MEDIUM The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged by an attacker to gain elevated privileges on a device and/or | Jun 24, 2022 | 6.8 | 23 | NO | NO |
CVE-2022-1746HIGH The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to prot | Jun 24, 2022 | 7.6 | 22 | NO | NO |
CVE-2022-1745MEDIUM The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker with physical access may use th | Jun 24, 2022 | 6.8 | 20 | NO | NO |
CVE-2022-1739MEDIUM The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root certificate. Use of a trusted root certificate ensures software | Jun 24, 2022 | 6.8 | 20 | NO | NO |
CVE-2022-1740MEDIUM The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export, and application export functionality rely on self-attestat | Jun 24, 2022 | 4.6 | 19 | NO | NO |
CVE-2022-1747MEDIUM The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker could l | Jun 24, 2022 | 4.6 | 16 | NO | NO |
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in w | Jun 19, 2023 | 2.4 | 12 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dominionvoting.
Media articles that mention a CVE ID that affects a product developed by Dominionvoting — matched by CVE ID, not by vendor name.