The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an attacker to directly access the operating system. An attacker could leverage this vulnerability to escalate privileges on a device and/or install malicious code.
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-154-01 | us government resource third party advisory mitigation |