← Latest briefing

Technology

Security researcher reveals disk encryption vulnerabilities affecting ATMs and embedded devices

Nine flaws identified in German firm CryptWare's CryptoPro Secure Disk software highlight broader software supply chain risks.

The short version

  • Security researcher Matt Burch revealed nine vulnerabilities in CryptoPro Secure Disk, a disk encryption and pre-boot authentication software produced by German firm CryptWare.
  • CryptWare patched the bugs across November and December, and Diebold Nixdorf issued fixes for the two flaws relevant to its ATM security systems.
  • The vulnerabilities could allow attackers to bypass integrity checks and gain full access to encrypted devices across various industries using Microsoft Windows and embedded systems.
  • The findings highlight software supply chain challenges, as applying fixes requires coordination between original vendors, software integrators, and end users.

Key facts

  • Security researcher Matt Burch presented findings at the Black Hat and Defcon security conferences detailing nine vulnerabilities in CryptWare's CryptoPro Secure Disk software.[Wired]
  • CryptWare patched all nine vulnerabilities in CryptoPro versions 7.7.2 and 7.7.3 in November and December.[Wired]
  • Diebold Nixdorf confirmed that two of the nine vulnerabilities affected its Vynamic Security Hard Disk Encryption system and released fixes in December.[Wired]
  • Diebold Nixdorf stated that the two relevant vulnerabilities could not have been exploited on their own to compromise its ATMs.[Wired]
  • CryptoPro software is used in ATMs, embedded devices, and by large organizations using Microsoft Windows.[Wired]

What remains uncertain

  • It is unclear how many deployed ATMs or enterprise devices have successfully installed the issued security patches, given the complex update and change-management procedures required for field systems.[Wired]

Sources