Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.20% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAILuksAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| Aplazada | Alta (8.4) | 0.14% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high… | |
| Aplazada | Alta (7.5) | 0.49% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform. | |
| Aplazada | Media (4.6) | 0.24% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM. | |
| Aplazada | Alta (7.2) | 0.67% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high… | |
| Aplazada | Alta (7.5) | 0.19% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations. | |
| Aplazada | Alta (7.5) | 0.31% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details. | |
| Modificada | Media (6.8) | 0.26% | — | Cpsd Cryptopro Secure Disk | 24/2/2026 | 17/6/2026 | The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before using BitLocker to decrypt the Windows partition. The system is located on a separate unencrypted partition which can be reached by anyone with access to the hard disk. Multiple checks are performed to… | |
| Modificada | Media (6.7) | 0.98% | — | Kidan Cryptopro Securedisk FOR BitlockerRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+6 | 26/8/2022 | 17/6/2026 | A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this… | |
| Modificada | Media (5.5) | 0.36% | — | Cryptopro CSP | 23/10/2020 | 17/6/2026 | CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows local users with the SeChangeNotifyPrivilege right to cause denial of service because user-mode input is mishandled during process creation. | |
| Modificada | Alta (7.8) | 0.41% | — | Cryptopro CSP | 23/10/2020 | 17/6/2026 | CryptoPro CSP through 5.0.0.10004 on 32-bit platforms allows Local Privilege Escalation (by local users with the SeChangeNotifyPrivilege right) because user-mode input is mishandled during process creation. An attacker can write arbitrary data to an arbitrary location in the kernel's address space. |