Researchers expose nine flaws in ATM encryption software and warn of broader supply-chain risks
Security researcher Matt Burch disclosed nine vulnerabilities in CryptoPro Secure Disk, a German encryption tool used in ATMs and other embedded systems, prompting patches from CryptWare and limited fixes from Diebold Nixdorf.
For half a decade, Matt Burch has focused on ATM security, and his latest work reveals nine exploitable bugs in CryptoPro Secure Disk, a disk-encryption and pre-boot authentication product from the German firm CryptWare. Presented at Black Hat and Defcon in Las Vegas, the flaws could bypass CryptoPro’s integrity checks and grant full access to encrypted hardware. CryptWare responded with two patch releases—version 7.7.2 in early November and 7.7.3 in early December—and Burch verified that the updates close the gaps.
Diebold Nixdorf, which incorporates CryptoPro in its Vynamic Security Suite, acknowledged that only two of the vulnerabilities relate to its ATM encryption and that the company issued its own fixes in December, noting the bugs alone would not let attackers compromise a Diebold Nixdorf ATM. The case underscores the layered challenges of software-supply-chain security: developers must issue patches, integrators must adapt them, and end users must apply them, a process often hampered by devices that remain in continuous operation. Burch also warned that AI tools now make it easier to discover such weaknesses, reducing the effectiveness of “security through obscurity.”
Why it matters
Flaws in widely used encryption software can expose critical infrastructure, and slow patch adoption magnifies the risk.
In this story
