ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

Security researcher Burch identified nine vulnerabilities in the CryptoPro Secure Disk software, which is used in ATMs and other embedded devices. The software manufacturer, CryptWare, has since released patches to address these flaws, which could have allowed unauthorized access to encrypted data.
Why it matters
The discovery highlights critical vulnerabilities in the software supply chain, where a single security flaw in a widely used component can impact multiple industries and financial networks.
At the Black Hat and Defcon security conferences in Las Vegas this month, Burch presented findings about nine vulnerabilities that have been fixed in disk encryption and pre-boot authentication software called CryptoPro Secure Disk. The flaws could have been exploited to bypass CryptoPro's integrity checks and gain full access to encrypted devices.
The report provides a technical overview of a security disclosure without editorializing.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in