Impact
CPSD CryptoPro Secure Disk for Bitlocker contains a default TPM PCR policy that does not verify the system boot state, constituting a CWE-1188 weakness. This flaw allows the TPM to be unsealed through an unintended execution path or from another hardware platform, potentially bypassing the intended protection mechanism and enabling an attacker to access data stored on the protected volume, thus compromising confidentiality.
Affected Systems
CPSD CryptoPro Secure Disk for Bitlocker (any version prior to 7.7.4) is affected by this vulnerability.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the EPSS score of < 1% suggests a low likelihood of exploitation, however the vulnerability remains serious. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves exploiting an unintended execution path that bypasses the TPM's PCR policy or using a different hardware platform to force the TPM to unseal. Without a patch or mitigation in place, an adversary could potentially retrieve the key material required to decrypt protected data.
OpenCVE Enrichment