For five years, security researcher Matt Burch has delved into the complexities of ATM security, uncovering that even minor software flaws can lead to significant vulnerabilities in ATM machines. His research has recently revealed nine critical vulnerabilities in the disk encryption and pre-boot authentication software known as CryptoPro Secure Disk, which is utilized in various ATMs and other embedded devices across multiple industries.
Burch presented his findings at the Black Hat and Defcon security conferences, highlighting that these vulnerabilities could enable attackers to bypass integrity checks, granting them full access to encrypted data. CryptoPro, developed by the German software firm CryptWare, primarily serves ATM manufacturers, including Diebold Nixdorf. However, it’s also marketed to a wide array of industries, complicating the task of addressing software vulnerabilities.
Burch expressed that while ATMs initiated his research path, the implications of his findings could extend much further. He noted the complex layers involved in financial networks often lead to overlooked bugs that may not receive adequate attention. CryptWare’s managing director, Uwe Saame, confirmed that the vulnerabilities were promptly addressed with two patch releases in late 2025, ensuring that their clients across various sectors, such as banking and healthcare, were informed of the necessary updates.
Diebold Nixdorf acknowledged that only two of the vulnerabilities pertained to their specific encryption system, with fixes implemented shortly after the vulnerabilities were disclosed. The overarching challenge remains that disseminating patches through the software supply chain can be cumbersome, especially when updates must be tailored to distinct customer systems which may not be easily updated in the field.
Experts have long cautioned against the pitfalls of depending on "security through obscurity" – the practice of keeping software undisclosed or locked away. Burch emphasized that advanced artificial intelligence tools can now facilitate vulnerability discovery even among those lacking specialized knowledge, intensifying the urgency for transparency in security products. He remarked, “AI really blows away the obscurity model,” indicating that anyone can potentially exploit flaws regardless of their understanding of the systems involved.
For further insights into these vulnerabilities, you can view the detailed reports from the National Vulnerability Database and follow the ongoing discussions in the cybersecurity community.