[36339] in bugtraq

home help back first fref pref prev next nref lref last post

Diebold Global Election Management System (GEMS) Backdoor Account

daemon@ATHENA.MIT.EDU (Jérôme" ATHIAS)
Wed Sep 1 00:36:32 2004

Date: 31 Aug 2004 20:38:15 -0000
Message-ID: <20040831203815.13871.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: "Jérôme" ATHIAS <jerome.athias@caramail.com>
To: bugtraq@securityfocus.com



Date:  Tue, 31 Aug 2004 00:38:05 -0400
Subject:  http://www.blackboxvoting.org/?q=node/view/78
 
BlackBoxVoting.org reported a vulnerability in the Diebold GEMS central tabulator.
 
A local authenticated user can enter a two-digit code in a certain "hidden" location 
to cause a second set of votes to be created on the system.  This second set of votes 
can be modified by the local user and then read by the voting system as legitimate 
votes, the report said.
 
GEMS 1.18.18, GEMS 1.18.19, and GEMS 1.18.23 are affected.
 
The vendor was reportedly notified on July 8, 2003.

 
Solution:  No vendor solution was available at the time of this entry.
 
Vendor URL:  www.diebold.com/dieboldes/GEMS.htm (Links to External Site) 
 

home help back first fref pref prev next nref lref last post