Security researcher Matt Burch presented findings at the Black Hat and Defcon security conferences in Las Vegas this month detailing nine vulnerabilities in CryptoPro Secure Disk, a disk encryption and pre-boot authentication product from the German software firm CryptWare. The flaws, now patched, could have allowed attackers to bypass the software’s integrity checks and gain full access to encrypted devices. CryptoPro is used in some ATMs, including as part of Diebold Nixdorf’s Vynamic Security Suite, but it is also sold to other embedded-device makers and to large organizations running Microsoft Windows, meaning the bugs carry implications beyond cash machines.

Burch, who has spent the past five years studying ATM security, said the vulnerabilities matter for the broader software supply chain. He noted that ATMs and financial networks have many layers, and that limited technical insight in those layers can cause bugs to be overlooked or not addressed. He also said the impact of the findings could be even higher outside of ATMs, given the wide deployment of CryptoPro in other industries.

CryptWare managing director Uwe Saame told Wired that the company patched the nine bugs in two phases, with CryptoPro version 7.7.2 released in early November and version 7.7.3 in early December. Burch said the company was prompt and collaborative during the disclosure process, and he verified that the patches fix the vulnerabilities he found. He also said he believes CryptWare distributed patch information to its customers, though the company does not appear to publicly release update notes.

Diebold Nixdorf spokesperson Michael Jacobsen told Wired that only two of the nine vulnerabilities are relevant to the ATM maker’s Vynamic Security Hard Disk Encryption system, which is where it uses CryptoPro software. Jacobsen said Diebold Nixdorf issued fixes for those two bugs in December, but that the flaws could not have been exploited on their own to compromise a Diebold Nixdorf ATM.

The case highlights the challenge of patching software across a supply chain, where fixes must move from a developer to a product integrator to end customers. In this instance, CryptWare had to release patches, then Diebold Nixdorf had to develop tailored updates, and then customers had to learn about and install those fixes, which can be difficult for systems running in the field or that cannot easily be paused. Jacobsen said that when a security issue is identified, Diebold Nixdorf assesses the impact, identifies affected products and configurations, develops needed updates, and notifies customers through standard channels, including the Global Security Portal, with deployment coordinated based on each customer’s operating model and service agreements.

Burch argued that the era of relying on security through obscurity is ending, especially as AI tools make it easier to analyze software and find vulnerabilities. He said AI removes the need for deep expertise to make progress in attacking a system, which raises the stakes for transparency in niche security products. The findings, he said, point to a need for broader awareness of how specialized software used in ATMs can introduce risks into critical systems across the US economy.

More cybersecurity news from TechManNews.