A series of critical vulnerabilities in a widely-used security software has left organizations and ATMs potentially exposed to compromise. The flaws, discovered by researcher Matt Burch, affect CryptoPro Secure Disk, a full-disk encryption (FDE) solution marketed to both corporate and ATM manufacturers.
Burch’s findings have sparked debate about the severity of the issues, with Diebold Nixdorf, one of the largest ATM manufacturers in the world, downplaying their significance. However, Burch describes CryptoPro as “foundational” to the security suite used by Diebold, suggesting that the vulnerabilities could be exploited to steal cash from ATMs.
The software weaknesses were discovered in the context of an ATM’s computing system, which is typically located at the top portion of the machine and is constructed with lower-grade steel or even plastic. Breaking into this area can be relatively easy for a determined attacker, as it only requires physical damage or the insertion of tools to access the locking mechanism.
The vulnerabilities reside in CryptoPro Secure Disk, which is integrated into various security suites used by organizations and ATM manufacturers. Specifically, Burch found that CryptoPro’s decryption process can default to mounting volumes in plaintext if a fail state is introduced during pre-boot, allowing hackers to potentially trick the system into decrypting data without proper authentication.
Furthermore, the researcher discovered that CryptoPro stores its own key material and configuration values on the disk itself, rather than in a more secure location. This weakness, combined with the plaintext issue, allows an attacker to gain full access to the program’s most guarded secrets. Additionally, Burch found that CryptoPro’s Secure Boot setup can be exploited to run malicious code.
The existence of these vulnerabilities raises concerns about the security of ATMs and organizations that rely on CryptoPro Secure Disk. As we’ve seen in recent years, ATM jackpotting attacks have become increasingly common, with over $20 million stolen from more than 700 reported incidents in 2025 alone.
While it’s unclear whether Burch’s findings will lead to a significant increase in ATM-related thefts, they serve as a reminder of the importance of robust security measures and regular software updates. In today’s digital landscape, organizations must stay vigilant against potential threats and vulnerabilities, especially when it comes to critical infrastructure like ATMs.
As for readers, the takeaway is clear: if you’re using CryptoPro Secure Disk or any other similar solution, ensure that you keep your software up-to-date and monitor your system closely for any signs of suspicious activity. Regular security audits and penetration testing can also help identify potential vulnerabilities before they’re exploited by attackers. By prioritizing cybersecurity and staying informed about the latest threats, we can all work together to protect our organizations and communities from potential harm.
Source: Dark Reading — 2026-07-10