Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
Published: 2026-08-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CryptoPro Secure Disk for Bitlocker fails to properly process decryption errors, enabling an attacker to mount an encrypted volume as plaintext. The flaw effectively bypasses Bitlocker encryption, exposing the sensitive data stored on the volume. The primary impact is a loss of confidentiality, allowing unauthorized reading of encrypted data. The weakness arises from inadequate error handling during decryption, which the software does not handle securely.

Affected Systems

The vulnerability affects CPSD's CryptoPro Secure Disk for Bitlocker installations earlier than version 7.7.4. Systems running any pre‑7.7.4 release are at risk. No alternative versions or products are listed as affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact vulnerability, while the EPSS score of < 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no known publicly curated exploits have been observed yet. The flaw allows an attacker who can trigger a decryption failure to mount an encrypted volume as plaintext, providing high confidentiality impact. The likely attack vector is local, requiring the attacker to initiate a decryption error on a CryptoPro‑managed volume, though an external exploitation path cannot be ruled out without further evidence.

Generated by OpenCVE AI on August 13, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official firmware upgrade to CryptoPro Secure Disk v7.7.4 or later
  • Restrict local access to CryptoPro‑managed volumes to privileged users only, ensuring that only authorized personnel can trigger mount operations
  • Enable and monitor system audit logs for attempted plaintext mounts of encrypted volumes, and flag any anomalous activity
  • Consider deploying an additional layer of file‑level encryption over the Bitlocker volume to add protection if a plaintext mount occurs

Generated by OpenCVE AI on August 13, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title CryptoPro Secure Disk Decryption Error Allows Plaintext Mount of Bitlocker Volumes
Weaknesses CWE-275
CWE-311

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-329
CWE-703
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Cpsd
Cpsd cryptopro Securedisk For Bitlocker
Vendors & Products Cpsd
Cpsd cryptopro Securedisk For Bitlocker

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title CryptoPro Secure Disk Decryption Error Allows Plaintext Mount of Bitlocker Volumes
Weaknesses CWE-275
CWE-311

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
References

Subscriptions

Cpsd Cryptopro Securedisk For Bitlocker
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-13T15:40:53.358Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59322

cve-icon Vulnrichment

Updated: 2026-08-13T15:40:49.438Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T15:17:30.353

Modified: 2026-08-31T19:33:11.197

Link: CVE-2025-59322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T19:30:03Z

Weaknesses
  • CWE-329

    Generation of Predictable IV with CBC Mode

  • CWE-703

    Improper Check or Handling of Exceptional Conditions