Critical Flaws in CryptoPro Secure Disk Threaten ATMs and Enterprise Systems
Security researcher **Matt Burch** has uncovered nine critical vulnerabilities in **CryptoPro Secure Disk**, a disk encryption and pre-boot authentication software from German firm **CryptWare**. These flaws, now patched, could have allowed attackers to bypass integrity checks and gain full access to encrypted devices. The widespread use of **CryptoPro** in ATMs and other critical infrastructure highlights significant software supply chain risks.
For five years, security researcher **Matt Burch** has delved into the complex world of ATM security, revealing how seemingly minor software flaws can expose significant financial risks. His latest findings, presented at the **Black Hat** and **Defcon** security conferences, detail nine vulnerabilities in **CryptoPro Secure Disk**.
### Unpacking the Vulnerabilities
These nine vulnerabilities, which have since been patched, could have been exploited to bypass **CryptoPro**'s integrity checks and gain complete access to encrypted devices. One such vulnerability is tracked as **CVE-2025-59327**.
**CryptoPro Secure Disk**, developed by **CryptWare**, is a cornerstone security solution for ATM manufacturers, including its integration into **Diebold Nixdorf**'s **Vynamic Security Suite**. However, its reach extends far beyond financial machines, securing various embedded devices and **Microsoft Windows** environments across critical sectors.
**Burch** noted the broader implications of his discoveries: "ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that." He emphasized that a lack of technical insight within complex financial networks often leads to overlooked or unaddressed bugs.
### The Patching Process and Supply Chain Challenges
**CryptWare** managing director **Uwe Saame** confirmed that the nine bugs were resolved in two phases with **CryptoPro** versions 7.7.2 (early November) and 7.7.3 (early December). **Saame** highlighted the extensive customer base for **CryptoPro**, spanning "automotive, banking, government agencies, manufacturing, research, finance, and healthcare," in addition to the ATM sector.
**Burch** commended **CryptWare**'s prompt and collaborative response throughout the disclosure process, validating the effectiveness of the patches.
While **CryptWare** does not publicly release update notes, **Saame** stated that all customers with maintenance agreements are notified in advance about security findings and resolution timelines. "As a rule, the new version is already available to our customers before its official publication," he added.
**Diebold Nixdorf** spokesperson **Michael Jacobsen** clarified that only two of the nine vulnerabilities were relevant to **Diebold Nixdorf**'s **Vynamic Security Hard Disk Encryption**. Fixes for these two bugs were issued in December, though **Jacobsen** asserted they could not have independently compromised a **Diebold Nixdorf** ATM.
This incident underscores the intricate challenges of the software supply chain. A patch from a developer must be followed by tailored fixes from companies integrating the product, and then successfully deployed by end-users β a complex process for widely distributed and continuously operating systems.
**Jacobsen** elaborated on **Diebold Nixdorf**'s approach: "when a security issue is identified, **Diebold Nixdorf** assesses the impact, identifies affected products and configurations, and develops any needed updates through our product security and engineering processes. We then notify impacted customers and provide updates through standard software distribution channels, including the Global Security Portal where applicable. For deployed ATMs, updates are coordinated with each customer based on their operating model, service agreements, and change-management processes."