VYPR

Secure Disk for Bitlocker

by CryptoPro

CVEs (7)

  • CVE-2025-59321CriAug 12, 2026
    risk 0.64cvss 9.8epss

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.

  • CVE-2025-59324CriAug 12, 2026
    risk 0.59cvss 9.1epss

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

  • CVE-2025-59323HigAug 12, 2026
    risk 0.55cvss 8.4epss

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for…

  • CVE-2025-59327HigAug 12, 2026
    risk 0.49cvss 7.5epss

    In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

  • CVE-2025-59319HigAug 12, 2026
    risk 0.47cvss 7.2epss

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for…

  • CVE-2025-59320MedAug 12, 2026
    risk 0.30cvss 4.6epss

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.

  • CVE-2025-59325Aug 12, 2026
    risk 0.00cvss epss

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.