Hidden functionality in ImageCast X - CVE-2022-1741

 

Hidden functionality in ImageCast X - CVE-2022-1741

Published: June 6, 2022


Vulnerability identifier: #VU63992
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-1741
CWE-ID: CWE-912
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Dominion Voting Systems
Affected software:
ImageCast X

Detailed vulnerability description

The vulnerability allows a local user to compromise vulnerable system

The vulnerability exists due to hidden functionality (backdoor) is present in software within the Terminal Emulator application. An authenticated attacker with physical access can use this functionality to gain elevated privileges on the device and install malicious code.


How to mitigate CVE-2022-1741

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Sources