ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
At the Black Hat and Defcon security conferences in Las Vegas this month, Burch unveiled findings regarding nine vulnerabilities in CryptoPro Secure Disk, a disk encryption and pre-boot authentication software. These flaws could enable exploitation of CryptoPro's integrity checks, granting full access to encrypted devices. CryptoPro, manufactured by the German software firm CryptWare, is marketed to ATM makers and is incorporated into some ATMs, such as those in Diebold Nixdorf's Vynamic Security Suite.
However, CryptoPro is also utilized by various embedded-device creators and large organizations running Microsoft Windows, highlighting the complexity of addressing bugs within a software supply chain that spans multiple industries. Burch notes that while ATMs initially sparked his interest, the broader implications of these findings could be more significant.
He emphasizes that, from the perspective of the financial network, numerous layers contribute to the implementation of software, often resulting in overlooked or unaddressed bugs. CryptoPro's managing director, Uwe Saame, confirmed to WIRED that the company patched the nine vulnerabilities in two updates: CryptoPro version 7.7.2 in early November and 7.7.3 in early December.
Burch affirmed that CryptWare was cooperative and transparent throughout the disclosure process, validating the effectiveness of the patches. Although CryptoPro does not publicly release update notes, Burch believes the company communicated information about the patches to its clients. Diebold Nixdorf spokesperson Michael Jacobsen stated that only two of the nine vulnerabilities affect Diebold Nixdorf's Vynamic Security Hard Disk Encryption, the system where their ATM maker employs CryptoPro software.
Jacobsen mentioned that Diebold Nixdorf applied fixes for these two bugs in December, but they could not have been exploited independently to compromise a Diebold Nixdorf ATM. The challenge of the software supply chain arises from the various stages involved in implementing fixes. Developers must release patches, companies implementing the product must tailor fixes, and customers must be informed and install the patches—a process that can be challenging for systems already in operation or difficult to update.
Diebold Nixdorf's spokesperson explained that when a security issue is discovered, the company assesses the impact, identifies affected products and configurations, and develops necessary updates following their product security and engineering processes. They then notify impacted customers and disseminate updates via standard software distribution channels, including the Global Security Portal.
For deployed ATMs, updates are coordinated with each customer based on their operating model, service agreements, and change-management processes. Security researchers have long cautioned against relying on "security through obscurity," as hiding software or keeping it locked away can expose vulnerabilities. This work has led to advancements in transparency and patch adoption within internet-of-things manufacturers and critical industries such as finance and medical device manufacturing.
However, Burch warns that the advent of AI systems, simplifying vulnerability evaluation even for researchers or attackers lacking specialized expertise, underscores the urgency of shedding light on niche security products. He asserts that AI has effectively dismantled the obscurity model, rendering it unnecessary to fully comprehend software workings to create substantial impacts.
Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.