ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

← Back to the feed

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

Wired · 3 hours ago

Security researcher Burch presented findings at Black Hat and Defcon detailing nine now-patched vulnerabilities in CryptoPro Secure Disk, a disk encryption and pre-boot authentication tool made by German firm CryptWare. The flaws could have let attackers bypass integrity checks and gain full access to encrypted devices, and the case highlights how deeply embedded, niche security software can spread through the supply chain, making bugs hard to spot and even harder to fully remediate once found.

CryptoPro is used in ATMs, including via Diebold Nixdorf's Vynamic Security Suite, but is also sold more broadly for embedded devices and Windows-based organisations. CryptWare fixed the nine bugs across two updates, versions 7.7.2 and 7.7.3, released in early November and December respectively; Diebold Nixdorf said only two of the flaws affected its systems and that these could not alone have compromised an ATM. Both companies said fixes were distributed to customers, though CryptoPro does not appear to publish public update notes. Burch warned that AI tools are eroding "security through obscurity," making it easier for researchers and attackers alike to probe niche, under-scrutinised software.

  • Nine flaws found and fixed in CryptoPro Secure Disk encryption software used in ATMs
  • Bugs could have bypassed integrity checks to fully access encrypted devices
  • Case shows AI is eroding "security through obscurity" for niche software

Software Technology

Read the full article at the source →