Security researcher Matt Burch disclosed nine vulnerabilities in CryptoPro Secure Disk, disk encryption and pre-boot authentication software used in ATMs and other critical systems, at the Black Hat and Defcon security conferences in Las Vegas this month. The bugs could have allowed attackers to circumvent CryptoPro's integrity protections and obtain complete access to encrypted devices. Burch's findings highlight not just overlooked ATM security gaps, but how the same software deployed across multiple sectors can create vulnerabilities in a wide range of essential systems.
The German software company CryptWare, which makes CryptoPro, fixed all nine bugs in two releases—version 7.7.2 in early November and version 7.7.3 in early December, according to managing director Uwe Saame. CryptoPro is sold to ATM manufacturers and appears in some ATMs as part of Diebold Nixdorf's Vynamic Security Suite, but it's also marketed as a security product for other embedded-device producers and large organizations running Microsoft Windows. Saame told WIRED that hundreds of CryptoPro customers operate across critical industries including automotive, banking, government agencies, manufacturing, research, finance, and healthcare, with extensive deployments in the ATM sector.
Burch says the company responded quickly and worked collaboratively during his disclosure, and he confirmed the patches successfully resolve the vulnerabilities he identified. Diebold Nixdorf spokesperson Michael Jacobsen told WIRED that only two of the nine flaws affect Diebold Nixdorf's Vynamic Security Hard Disk Encryption, the system where the ATM maker incorporates CryptoPro software. Jacobsen stated that Diebold Nixdorf released fixes for those two bugs in December, but noted they couldn't have been exploited alone to compromise a Diebold Nixdorf ATM. "ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that," Burch says.
The core challenge stems from the software supply chain, where multiple steps are required to actually deploy fixes in real-world systems. A developer must issue a patch, then companies that integrate the product into their own software need to create a customized fix, and finally customers must learn about and install that patch—which can be difficult for systems operating in the field or that can't easily be stopped and updated. Burch notes that from the perspective of ATMs and the financial network, there are many layers, and as a result things get deployed a certain way with limited technical oversight—bugs can be missed or they don't get fixed. CryptWare maintains service agreements with all customers and alerts them ahead of time about any security discoveries and the company's schedule for addressing them, with new versions typically available to customers before official publication, Saame says.
For deployed ATMs, Jacobsen explained that updates are coordinated with each customer based on their operating model, service agreements, and change-management processes after Diebold Nixdorf assesses impact, identifies affected products and configurations, and develops needed updates through product security and engineering procedures. The findings underscore how widely distributed security software can silently propagate weaknesses across sectors far beyond the original use case where flaws are discovered. Organizations that depend on third-party encryption solutions may unknowingly inherit risks that require coordinated, multi-step remediation—a reality that demands stronger visibility into the software components embedded in critical infrastructure.

