Impact
CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 keeps the initramfs contents unencrypted, allowing an attacker who can examine the device offline to recover cryptographic keys and other confidential information. The flaw directly undermines the confidentiality guarantees normally provided by disk‑level encryption.
Affected Systems
The affected product is CPSD CryptoPro Secure Disk, a Bitlocker‑based disk encryption solution. Versions earlier than 7.7.4 are impacted. No specific subsidiary names are listed.
Risk and Exploitability
Exploitation requires physical or direct offline access to the pre‑encrypted initramfs, a high‑effort scenario that reduces the likelihood of real‑world attacks, as indicated by an EPSS score of less than 1%. The CVSS score of 7.5 signals high severity. The vulnerability is not listed in the CISA KEV catalog, suggesting the absence of active, widespread exploitation.
OpenCVE Enrichment