Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
Published: 2026-08-12
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CryptoPro Secure Disk for Bitlocker software, prior to version 7.7.4, fails to verify LUKS encrypted partitions. Because the encryption is detected, the program skips all CryptoPro file integrity checks. An attacker who can modify the encrypted data can therefore insert tampered or malicious content without detection, leading to permanent compromise of data integrity.

Affected Systems

The vulnerability affects the CryptoPro Secure Disk for Bitlocker product. Specifically, all releases before v7.7.4 are impacted. No vendor‑provided version list is included in the data, so users should consider any pre‑7.7.4 installation as at risk.

Risk and Exploitability

The CVSS score of 9.1 reflects a critical severity. The EPSS score is less than 1%, indicating a very low but nonzero probability of exploitation. The flaw is listed outside the CISA KEV catalog, indicating no confirmed widespread exploitation. Based on the description, the attack vector is likely local or requires privileged access to the encrypted volume to inject malicious data. Once the integrity checks are bypassed, the attacker could persist tampering that would be treated as legitimate by the system.

Generated by OpenCVE AI on August 13, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CryptoPro Secure Disk to version 7.7.4 or newer.
  • If an upgrade is not possible, disable LUKS encryption or use an alternative encryption mechanism that enforces integrity checks.
  • Implement external file integrity monitoring or digital signatures to detect tampered data.

Generated by OpenCVE AI on August 13, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title CryptoPro Secure Disk Skips Integrity Checks on LUKS Encryption, Allowing Tampered Data

Thu, 13 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title CryptoPro Secure Disk Skips Integrity Checks When LUKS Encryption Is Detected
Weaknesses CWE-345

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-347
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Cpsd
Cpsd cryptopro Securedisk For Bitlocker
Vendors & Products Cpsd
Cpsd cryptopro Securedisk For Bitlocker

Thu, 13 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title CryptoPro Secure Disk Skips Integrity Checks When LUKS Encryption Is Detected
Weaknesses CWE-345

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
References

Subscriptions

Cpsd Cryptopro Securedisk For Bitlocker
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-13T15:38:53.234Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59324

cve-icon Vulnrichment

Updated: 2026-08-13T15:38:50.429Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T15:17:31.030

Modified: 2026-09-01T21:09:48.053

Link: CVE-2025-59324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:15:03Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature