Executive brief
Entrust nShield HSM (Hardware Security Module) devices store and protect cryptographic keys and perform security operations for enterprises. An attacker with physical access can bypass tamper detection, open the chassis undetectably, and access the JTAG connector to gain debug access and escalate privileges, potentially exposing protected cryptographic material and enabling persistent compromise of the device.
Technical details
This vulnerability (F02) is a hardware-level privilege escalation via JTAG access in the Chassis Management Board (Cosmo SoC) found in nShield HSM devices. The root cause is the lack of JTAG security protections and the absence of secure boot mechanisms on the ARM SoC; an attacker with physical access can open the chassis by bypassing the tamper label without leaving evidence, locate the exposed JTAG header, and use standard JTAG tools to read/modify firmware and access internal memory (flash, SRAM). Preconditions include physical proximity to the device. An attacker can then modify the Cosmo firmware persistently, disable tamper protections, control boot processes, and maintain undetectable persistence. Patches are available in version 13.6.12 (LTS) and 13.9.0 (STS).
Affected products
- Entrust nShield Connect XC through 13.6.11, or 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
- Entrust nShield 5c through 13.6.11, or 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
- Entrust nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
Timeline
- 2025-12-02: disclosed
- 2025-09-22: patched: Patches available in version 13.6.12 (LTS) and 13.9.0 (STS)