CVE-2025-59321
Deferred Deferred - Pending Action

Default TPM PCR Policy Bypass in CryptoPro Secure Disk

Vulnerability report for CVE-2025-59321, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-31

Assigner: MITRE

Description

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
cpsd crypto_pro_secure_disk to 7.7.4 (exc)
cpsd cryptopro_secure_disk to 7.7.4 (exc)
cpsd cryptopro_secure_disk_for_bitlocker to 7.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CPSD CryptoPro Secure Disk for Bitlocker before version 7.7.4 has a default TPM PCR policy that does not properly account for the system boot state. This flaw allows the TPM to be unsealed through an unintended execution path or even from a different hardware platform.

Detection Guidance

Detection requires checking the installed version of CPSD CryptoPro Secure Disk for Bitlocker. If the version is below 7.7.4, the system is vulnerable. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow unauthorized access to encrypted data if an attacker exploits the unintended TPM unsealing path or uses a different hardware platform. It may lead to data breaches or unauthorized system access.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strong encryption and access controls, such as GDPR or HIPAA. Unauthorized data access may result in legal penalties or loss of certification.

Mitigation Strategies

Update CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later to address the default TPM PCR policy issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59321. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart