EletiofeATM Flaws Reveal Key Weaknesses in the Software Supply...

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

-

- Advertisment -

For the past five years, security researcher Matt Burch has immersed himself in the esoteric and high-stakes world of ATM security, in which small software flaws can sometimes expose cold, hard cash. As Burch has bored deeper into the computers powering these digital lock boxes—and continued to find vulnerabilities in key digital security systems—he has started working to raise the alarm, not just about overlooked ATM flaws, but about how that same software used in other industries can introduce weaknesses in an array of critical systems.

At the Black Hat and Defcon security conferences in Las Vegas this month, Burch presented findings about nine vulnerabilities that have been fixed in disk encryption and pre-boot authentication software called CryptoPro Secure Disk. The flaws could have been exploited to bypass CryptoPro’s integrity checks and gain full access to encrypted devices.

Made by the German software firm CryptWare, CryptoPro is marketed to ATM makers and is used in some ATMs, including as part of Diebold Nixdorf’s Vynamic Security Suite. But CryptoPro is also sold as a security solution for other embedded-device makers, as well as big organizations using Microsoft Windows, underscoring the supply chain challenge of addressing bugs when software is widely implemented in numerous industries.

“ATMs are what brought me down this path, but I think there may be an even higher impact of these findings beyond that,” Burch says. “From the perspective of ATMs and the financial network, there are a lot of layers, and I think as a result of that, things just get implemented a certain way and then there’s limited technical insight—bugs can get overlooked or they don’t get addressed.”

CryptWare managing director Uwe Saame tells WIRED that the company patched the nine bugs in two phases with CryptoPro version 7.7.2 in early November and 7.7.3 in early December. He adds that there are hundreds of CryptoPro customers across critical industries including “automotive, banking, government agencies, manufacturing, research, finance, and healthcare. There are also extensive installations in the ATM sector.”

Burch says the company was prompt and collaborative throughout his disclosure process and he validated that the patches actually fix the vulnerabilities he found.

While CryptoPro does not publicly release update notes, Saame says that the company has maintenance agreements with all customers and notifies them in advance about any security findings as well as the company’s timeline for resolving them. “As a rule, the new version is already available to our customers before its official publication,” he says.

Diebold Nixdorf spokesperson Michael Jacobsen tells WIRED in a statement that only two of the nine vulnerabilities are relevant to Diebold Nixdorf’s Vynamic Security Hard Disk Encryption, the system where the ATM maker uses CryptoPro software. Jacobsen says that Diebold Nixdorf issued fixes related to those two bugs in December, but that they could not have been exploited on their own to compromise a Diebold Nixdorf ATM.

In ATMs, embedded devices, and enterprise security more broadly, the challenge of the software supply chain comes from all of the steps to actually apply fixes in the world. As in this case, a developer has to release a patch, then companies that implement the product in their own software need to develop a tailored fix, and then customers need to actually hear about and install that patch—which can be difficult for systems that are running in the field or can’t easily be paused and updated.

Speaking generally about this challenge, Jacobsen, the Diebold Nixdorf spokesperson, says that “when a security issue is identified, Diebold Nixdorf assesses the impact, identifies affected products and configurations, and develops any needed updates through our product security and engineering processes. We then notify impacted customers and provide updates through standard software distribution channels, including the Global Security Portal where applicable. For deployed ATMs, updates are coordinated with each customer based on their operating model, service agreements, and change-management processes.”

Latest news

Why Food Keeps Making Everybody Sick This Summer

This summer, every meal feels like a risk.Just as the US is recovering from a major cyclospora outbreak stemming...

You Know Who Really Hates AI? Insurance Claims Adjusters

On the job review platform Glassdoor, one faction hates artificial intelligence more than any other.“Pushing AI to the point...

The 9 Best MagSafe Phone Grips for Your Butter Fingers (2026)

Other MagSafe Grips We’ve TestedSpigen OM104 MagSafe Phone Grip: The OM104 is a phone/grip combo accessory for MagSafe and...

Google Maps Now Shows ‘Lake America’ Instead of Lake Ontario

Lake Ontario is no more on Google Maps in the US. Google changed the name of the easternmost of...
- Advertisement -

Best Mesh Wi-Fi Systems (2026): I Tested Them All

Most of us are stuck placing our router in a less-than-optimal spot, depending on where the internet connection comes...

Why the Hottest New Wearables Want to Be Ignored

There’s a new kind of gadget on shelves, designed for you to ignore it 99 percent of the time—it...

Must read

Why Food Keeps Making Everybody Sick This Summer

This summer, every meal feels like a risk.Just as...

You Know Who Really Hates AI? Insurance Claims Adjusters

On the job review platform Glassdoor, one faction hates...
- Advertisement -

You might also likeRELATED
Recommended to you