CVE-2025-59323
Deferred Deferred - Pending Action

CPSD CryptoPro Secure Disk DataStore Integrity Validation Flaw

Vulnerability report for CVE-2025-59323, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-31

Assigner: MITRE

Description

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cpsd crypto_pro_secure_disk to 7.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 does not check if the DataStore, which holds configuration and cryptographic data, has been tampered with. Attackers can create malicious DataStore contents to disrupt service or run code with high privileges.

Detection Guidance

The provided CVE data does not include specific detection methods or commands for identifying this vulnerability on a network or system. Manual inspection of the DataStore filesystem and validation of its integrity is recommended, but no concrete steps are provided in the context.

Impact Analysis

This flaw could allow attackers to crash the system or execute arbitrary code with elevated permissions, potentially leading to data theft, system compromise, or denial of service.

Compliance Impact

The vulnerability allows crafted DataStore contents to impact service availability or enable code execution with high privileges. This could lead to unauthorized access or disruption of encrypted data storage, potentially violating data integrity and confidentiality requirements under GDPR and HIPAA.

Mitigation Strategies

Update CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later to address the integrity validation flaw in the DataStore.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59323. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart