AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2025-59320

MEDIUM · CVSS 4.6 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

CPSD CryptoPro Secure Disk for Bitlocker versions prior to 7.7.4 are vulnerable due to the storage of TPM2.0 secrets in serialized format within unused disk sectors. An unauthenticated attacker with physical access can exploit this weakness to recover sensitive information and potentially unseal the TPM, compromising the security of encrypted data. Organizations using this software should prioritize remediation to mitigate risks associated with physical access vulnerabilities.

CVE
CVE-2025-59320
Severity
MEDIUM
CVSS
4.6
EPSS
0.18%

Original NVD Description

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.