CVE-2022-1740CWE-1283
2.2.2 MUTABLE ATTESTATION OR MEASUREMENT REPORTING DATA CWE-1283
Medium · published June 24, 2022
What it is
The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export, and application export functionality rely on self-attestation mechanisms. An attacker could leverage this vulnerability to disguise malicious applications on a device.
The record
Technical detail
- CVSS v3.1
- 4.6 · MEDIUM
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00227 · 13.3th percentile
- Weakness
- CWE-1283 · Mutable Attestation or Measurement Reporting Data
- Published
- 2022-06-24T15:00Z
EPSS history
Timeline