Encrypting Voter Data With a Broken Cipher
During a security assessment of an election management platform, the sensitive voter record export feature was found to use AES encryption in CBC mode without any message authentication code. This design allowed ciphertext to be modified in predictable ways, ballot export files to be silently corrupted, and — under specific conditions — plaintext content to be partially recovered without the encryption key.