CVE-2025-59325
Received Received - Intake

CryptoPro Secure Disk for Bitlocker initramfs Plaintext Exposure

Vulnerability report for CVE-2025-59325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: MITRE

Description

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cpsd crypto_pro_secure_disk_for_bitlocker to 7.7.4 (exc)
cpsd cryptopro_secure_disk_for_bitlocker to 7.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 does not encrypt the initramfs contents. This allows attackers to recover secrets and cryptographic details offline by accessing unencrypted data in the initramfs.

Detection Guidance

To detect this vulnerability, check the installed version of CPSD CryptoPro Secure Disk for Bitlocker. If the version is below 7.7.4, the system is vulnerable. Compare the version against the latest release.

Impact Analysis

An attacker could extract sensitive information like encryption keys or passwords from the unencrypted initramfs. This could lead to unauthorized access to encrypted data or system compromise.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR and HIPAA by exposing sensitive data. Organizations using this software could face compliance violations and legal penalties.

Mitigation Strategies

Update CPSD CryptoPro Secure Disk for Bitlocker to version 7.7.4 or later to ensure initramfs contents are properly encrypted.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-59325. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart