CVE-2022-48506
low-risk
Published 2023-06-19
A flawed pseudorandom number generator in Dominion Voting Systems ImageCast Precinct (ICP and ICP2) and ImageCast Evolution (ICE) scanners allows anyone to determine the order in which ballots were cast from public ballot-level data, allowing deanonymization of voted ballots, in several types of scenarios. This issue was observed for use of the following versions of Democracy Suite: 5.2, 5.4-NM, 5.5, 5.5-A, 5.5-B, 5.5-C, 5.5-D, 5.7-A, 5.10, 5.10A, 5.15. NOTE: the Democracy Suite 5.17 EAC Certificate of Conformance mentions "Improved pseudo random number algorithm," which may be relevant.
Do I need to act?
-
0.07% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
2
CVSS 2.4/10
Low
PHYSICAL
/ LOW complexity
Affected Products (11)
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Democracy Suite
Affected Vendors
References (8)
Product
https://dvsorder.org
Third Party Advisory
https://freedom-to-tinker.com/2023/06/14/security-analysis-of-the-dominion-image...
Product
https://dvsorder.org
Third Party Advisory
https://freedom-to-tinker.com/2023/06/14/security-analysis-of-the-dominion-image...
26
/ 100
low-risk
Severity
10/34 · Low
Exploitability
0/34 · Minimal
Exposure
16/34 · Moderate