Description
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.
Published: 2026-08-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 keeps the initramfs contents unencrypted, allowing an attacker who can examine the device offline to recover cryptographic keys and other confidential information. The flaw directly undermines the confidentiality guarantees normally provided by disk‑level encryption.

Affected Systems

The affected product is CPSD CryptoPro Secure Disk, a Bitlocker‑based disk encryption solution. Versions earlier than 7.7.4 are impacted. No specific subsidiary names are listed.

Risk and Exploitability

Exploitation requires physical or direct offline access to the pre‑encrypted initramfs, a high‑effort scenario that reduces the likelihood of real‑world attacks, as indicated by an EPSS score of less than 1%. The CVSS score of 7.5 signals high severity. The vulnerability is not listed in the CISA KEV catalog, suggesting the absence of active, widespread exploitation.

Generated by OpenCVE AI on August 22, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CPSD CryptoPro Secure Disk to version 7.7.4 or later to ensure initramfs contents are encrypted.
  • Verify that the encrypted partition option for the initramfs is enabled according to vendor guidelines.
  • Conduct periodic integrity checks on the initramfs and boot files to confirm they remain encrypted and mitigated against offline retrieval.

Generated by OpenCVE AI on August 22, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unencrypted Initramfs Enables Offline Retrieval of Crypto Keys in CPSD CryptoPro Secure Disk

Sat, 22 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Initramfs Unencrypted in CryptoPro Secure Disk Exposes Secrets
Weaknesses CWE-200

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-311
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Initramfs Unencrypted in CryptoPro Secure Disk Exposes Secrets
Weaknesses CWE-200

Thu, 13 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Cpsd
Cpsd cryptopro Secure Disk
Vendors & Products Cpsd
Cpsd cryptopro Secure Disk

Wed, 12 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.
References

Subscriptions

Cpsd Cryptopro Secure Disk
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-18T19:53:36.027Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59325

cve-icon Vulnrichment

Updated: 2026-08-18T13:42:55.364Z

cve-icon NVD

Status : Received

Published: 2026-08-12T14:17:46.587

Modified: 2026-08-18T20:17:09.837

Link: CVE-2025-59325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T13:30:17Z

Weaknesses
  • CWE-311

    Missing Encryption of Sensitive Data