Researcher finds nine flaws in CryptoPro Secure Disk used in ATMs

This digest was compiled by AI from multiple sources — links to the originals are below.
Security researcher Matt Burch presented nine vulnerabilities in CryptoPro Secure Disk at Black Hat and Defcon in Las Vegas. The flaws could bypass integrity checks and grant full access to encrypted devices. CryptWare patched the issues in versions 7.7.2 and 7.7.3, while Diebold Nixdorf fixed two relevant bugs in December.
Key Facts
- Matt Burch presented nine vulnerabilities in CryptoPro Secure Disk at Black Hat and Defcon in Las Vegas.
- The flaws could bypass CryptoPro's integrity checks and grant full access to encrypted devices.
- CryptWare patched the nine bugs in CryptoPro versions 7.7.2 in early November and 7.7.3 in early December.
- Diebold Nixdorf stated only two vulnerabilities were relevant to its Vynamic Security Hard Disk Encryption and issued fixes in December.
- CryptoPro Secure Disk is used in ATMs, including as part of Diebold Nixdorf's Vynamic Security Suite, and is also sold for other embedded devices and Windows systems.
Vulnerability Disclosure
Matt Burch presented findings on nine vulnerabilities in CryptoPro Secure Disk at the Black Hat and Defcon security conferences in Las Vegas. The flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices. CryptoPro Secure Disk is made by German software firm CryptWare and marketed to ATM makers. The software is used in some ATMs, including as part of Diebold Nixdorf's Vynamic Security Suite. CryptoPro is also sold as a security solution for other embedded-device makers and organizations using Microsoft Windows.
Vendor Response
CryptWare managing director Uwe Saame said the company patched the nine bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December. Burch said the company was prompt and collaborative throughout his disclosure process and he validated that the patches actually fix the vulnerabilities. Diebold Nixdorf spokesperson Michael Jacobsen said only two of the nine vulnerabilities are relevant to Diebold Nixdorf's Vynamic Security Hard Disk Encryption. Jacobsen said Diebold Nixdorf issued fixes related to those two bugs in December, but they could not have been exploited on their own to compromise a Diebold Nixdorf ATM.
Supply Chain Implications
Burch said ATMs brought him down this path, but he thinks there may be an even higher impact of these findings beyond ATMs. He noted that from the perspective of ATMs and the financial network, there are many layers and limited technical insight, so bugs can get overlooked or not addressed. The challenge of the software supply chain comes from all the steps to actually apply fixes in the world, across ATMs, embedded devices, and enterprise security.