During security conferences held in Las Vegas this month, Burch presented findings regarding nine vulnerabilities discovered in a disk encryption and pre-boot authentication software called CryptoPro Secure Disk. These flaws could have been exploited to bypass the software integrity checks and gain full access to encrypted devices.
Developed by the German software firm CryptWare, CryptoPro is primarily marketed to ATM manufacturers and is utilized in various automated teller machines, including within Diebold Nixdorf's Vynamic Security Suite. However, the software is also distributed as a security solution for other embedded device makers and large organizations running Microsoft Windows, highlighting the complex supply chain challenges that arise when software is widely deployed across numerous industries.
Burch notes that while automated teller machines initiated this research path, the broader implications of these findings extend far beyond them. Within financial networks and ATM infrastructures, multiple operational layers exist, which often leads to implementations happening in specific ways with limited technical visibility, allowing bugs to be overlooked or left unaddressed.
CryptWare managing director Uwe Saame stated that the company successfully resolved the nine bugs across two phases using CryptoPro version 7.7.2 in early November and version 7.7.3 in early December. According to Burch, the company maintained a collaborative approach throughout the disclosure process, and he independently verified that the deployed patches effectively resolved the identified vulnerabilities. Although the firm does not publicly publish standard update release notes, Burch believes that patch information was successfully communicated directly to customers.
Diebold Nixdorf spokesperson Michael Jacobsen clarified in a statement that only two of the nine total vulnerabilities directly affect Diebold Nixdorf's Vynamic Security Hard Disk Encryption system, where the company integrates CryptoPro technology. Jacobsen explained that necessary fixes for those two specific bugs were released in December, and noted that they could not have been independently leveraged to compromise an operational Diebold Nixdorf ATM.
Across embedded technology, enterprise security, and automated teller machines, software supply chain hurdles stem primarily from the multi-step reality of applying updates in practical environments. As demonstrated here, an initial software developer must issue a patch, subsequent implementers must create customized fixes, and end users must become aware of the update and install it, which presents difficulties for critical systems running constantly in the field.
Addressing these industry-wide hurdles generally, Jacobsen explained that when a security issue is identified, the organization assesses the impact, determines affected configurations, and develops updates through standard engineering pipelines before notifying impacted clients through distribution channels like the Global Security Portal. Deployment on active machinery is subsequently coordinated based on individual customer operating models and service agreements.
Security researchers have long cautioned against relying on security through obscurity by attempting to conceal software inner workings. While critical sectors like financial institutions and medical device manufacturers have made strides in transparency, Burch emphasizes that the rise of artificial intelligence makes evaluating software and locating vulnerabilities accessible even to actors without deep granular expertise, making scrutiny of niche security tools more vital than ever.
Burch emphasizes that advanced technology effectively disrupts traditional obscurity models, removing the strict necessity of fully understanding complex internal mechanics to analyze potential security impacts.



















