CISA Releases Advisory on Flaws in Dominion Voting Machines; Director Jen Easterly Quoted

The Cybersecurity and Infrastructure Security Agency has issued an advisory saying it found no evidence that vulnerabilities in Dominion in-person voting systems were exploited in any elections, CBS News reported Friday.

According to the advisory, CISA identified nine vulnerabilities in certain versions of Dominion Voting Systems ImageCast X software, including improper verification of cryptographic signatures, authentication bypass by spoofing, incorrect privilege assignment and origin validation error.

The agency said exploitation of these flaws would require physical access to ImageCast X devices, capability to alter files before they are uploaded to such devices or access to the Election Management Systems.

Over the past week, we've been working with election officials on information regarding vulnerabilities affecting certain versions of Dominion Voting Systems' software,” CISA Director Jen Easterly, a 2022 Wash100 Award winner, said in a statement Friday. "Today, we are releasing this information publicly." 

CISA recommends several measures election officials should take to prevent the exploitation of these vulnerabilities.

These include reaching out to Domain Voting Systems to determine which software updates need to be implemented; ensuring all affected devices are physically protected before, during and after voting; closing any background application windows on each ImageCast X device; disabling the “Unify Tabulator Security Keys” feature on the EMS and ensuring new cryptographic keys are used for each election; and conducting rigorous post-election tabulation audits.

Many of these mitigations, which are typically standard practice in jurisdictions where these devices are in use, are able to detect exploitation of these vulnerabilities and in many cases would prevent attempts entirely if diligently applied, making it very unlikely that a malicious actor could exploit these vulnerabilities to affect an election,” added Easterly. 

Share the Post:

Related Posts

5 Key Values of the Wash100 Award

The government contracting industry thrives on leadership, innovation and undeniable contributions to key missions. The Wash100 Award, established by Executive Mosaic in 2014, is an annual recognition of the GovCon...

Top 5 Most Popular Wash100 Winners of All Time

The 100 leaders named to the Wash100 every year by premier government contracting events and media company Executive Mosaic are all renowned members of the federal services ecosystem. But only...

Popular Vote Winner Judi Dotson On What Wash100 Means to Her

In 2024, Judi Dotson, president of the global defense sector at Booz Allen Hamilton, has earned a reputation for making Wash100 history. In March, she became the first Wash100 recipient...