Established Fact
[Established Fact – As to SQL port configuration and demonstrated vulnerability] Forensic analysis of Dominion’s Democracy Suite in multiple jurisdictions established that SQL Server port 1433 was configured to accept connections from any IP address worldwide. Port 1433 is the standard network port for Microsoft SQL Server – the database engine underlying the Democracy Suite. An open, world-accessible SQL Server port means that any actor with valid database credentials could directly connect to the election database from any internet-connected device and execute queries against it: inserting, modifying, or deleting records in the vote database without passing through any certified application interface and without generating any entry in the certified application-level audit trail. The Mesa County forensic team demonstrated this vulnerability empirically: using a non-Dominion workstation and an iPhone SQL client, they were able to directly modify election database records in a Mesa County Democracy Suite environment. Whether this architectural deficiency – present in the certified deployment configuration shipped to all Democracy Suite jurisdictions – was exploited in any Pennsylvania county is a forensic question that has not been answered, because the external IP transmission logs from the Fulton County forensic examination have not been fully disclosed.
Citations
Douglas Gould, “Report #2: Forensic Examination and Analysis Report” (Feb. 28, 2022), analyzing forensic images of Mesa County’s Dominion D-Suite 5.11-CO EMS server (the certified version used in the 2020 election)
Cybersecurity and Infrastructure Security Agency, ICS Advisory (ICSA-22-154-01): Dominion Voting Systems Democracy Suite ImageCast X (June 3, 2022), discussed in CyberScoop at https://cyberscoop.com/dominion-vulnerability-cisa-advisory-2020/ and acknowledged at https://www.eac.gov/news/2022/06/03/eac-issues-advisory-dominion-imagecast-x-component
Fulton County v. Dominion Voting Systems, Inc., No. 277 MD 2021, Civil Complaint (Fulton Cty. Ct. of Common Pleas, Sept. 20, 2022), available at https://www.co.fulton.pa.us/files/live-folders/FC-vs-Dom/COMPLAINT.v6.09.20.22.pdf
Fulton County, PA Speckin Forensics Report, September 15, 2022 https://drive.google.com/file/d/1xHDI_qbZbFSBu_cJ-BEP4WNxSjc-e1Z_/view?usp=drive_link