Impact
CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 writes TPM 2.0 secret data into unused sectors of the system disk while serializing the data. This leftover information can be read by any attacker who obtains physical access to the disk. With these secrets the attacker can construct an environment to unseal the TPM, potentially exposing all keys and data protected by the device.
Affected Systems
All installations of CPSD CryptoPro Secure Disk for Bitlocker using versions earlier than 7.7.4 are affected. No other vendors or products are listed, and the vendor is implied to be CPSD.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity. Physical access is required, making the attack vector local and unauthenticated. The EPSS score is not available, and the vulnerability is not present in the CISA KEV catalog, suggesting limited documented exploitation. An attacker can recover the secrets by reading raw disk sectors, a relatively straightforward operation once the machine is compromised.
OpenCVE Enrichment