CVE-2025-59323
Received Received - Intake

CPSD CryptoPro Secure Disk DataStore Integrity Validation Flaw

Vulnerability report for CVE-2025-59323, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: MITRE

Description

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high privilege.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cpsd crypto_pro_secure_disk to 7.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 does not check if the DataStore, which holds configuration and cryptographic data, has been tampered with. Attackers can create malicious DataStore contents to disrupt service or run code with high privileges.

Impact Analysis

This flaw could allow attackers to crash the system or execute arbitrary code with elevated permissions, potentially leading to data theft, system compromise, or denial of service.

Mitigation Strategies

Update CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later to address the integrity validation flaw in the DataStore.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59323. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart