Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
Published: 2026-08-12
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 writes TPM 2.0 secret data into unused sectors of the system disk while serializing the data. This leftover information can be read by any attacker who obtains physical access to the disk. With these secrets the attacker can construct an environment to unseal the TPM, potentially exposing all keys and data protected by the device.

Affected Systems

All installations of CPSD CryptoPro Secure Disk for Bitlocker using versions earlier than 7.7.4 are affected. No other vendors or products are listed, and the vendor is implied to be CPSD.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate severity. Physical access is required, making the attack vector local and unauthenticated. The EPSS score is not available, and the vulnerability is not present in the CISA KEV catalog, suggesting limited documented exploitation. An attacker can recover the secrets by reading raw disk sectors, a relatively straightforward operation once the machine is compromised.

Generated by OpenCVE AI on August 12, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later to eliminate the insecure storage of TPM secrets.
  • Limit physical access to the affected machines through hardware security controls, secure rooms, or tamper‑evident enclosures.
  • If upgrading is not immediately feasible, perform secure erasure or overwrite of unused disk sectors to remove residual TPM secrets.
  • Deploy monitoring for unauthorized physical access or disk imaging attempts.

Generated by OpenCVE AI on August 12, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Cpsd
Cpsd cryptopro Secure Disk
Vendors & Products Cpsd
Cpsd cryptopro Secure Disk

Wed, 12 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title TPM Secret Exposure via Unused Disk Sectors in CryptoPro Secure Disk for Bitlocker

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-922
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
References

Subscriptions

Cpsd Cryptopro Secure Disk
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-12T19:26:22.530Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59320

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-12T15:17:29.787

Modified: 2026-08-31T19:33:11.197

Link: CVE-2025-59320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:45:02Z

Weaknesses
  • CWE-922

    Insecure Storage of Sensitive Information