Security researcher Matt Burch has focused on ATM security for five years, uncovering vulnerabilities that could expose financial systems to risks. At the Black Hat and Defcon security conferences in Las Vegas, Burch presented findings on nine vulnerabilities in CryptoPro Secure Disk software, which is used in ATMs and other embedded devices. The flaws could allow unauthorized access to encrypted devices.
CryptoPro, developed by German firm CryptWare, is part of Diebold Nixdorf's Vynamic Security Suite. Burch emphasized that issues in ATM software reflect broader challenges in the software supply chain, where vulnerabilities in widely used software can affect multiple industries.
CryptWare's managing director, Uwe Saame, confirmed that the company addressed the vulnerabilities with updates in November and December. Burch noted that the company was responsive during the disclosure process and validated the effectiveness of the patches.
Diebold Nixdorf spokesperson Michael Jacobsen stated that only two of the vulnerabilities were relevant to their systems and that fixes were issued in December. He explained that addressing security issues involves assessing impacts, identifying affected products, and notifying customers.
Burch highlighted the importance of transparency in security, noting that AI advancements make it easier to identify vulnerabilities in software. He warned against relying on obscurity for security, advocating for increased awareness and patch adoption in critical industries.