Executive brief
Entrust nShield hardware security modules (HSMs) are appliances used to protect cryptographic keys and perform secure operations. An attacker with physical access can persistently modify the Chassis Management Board firmware without any security restrictions or verification, compromising the boot integrity and allowing undetectable, long-term control of the device's security functions including tamper event reporting.
Technical details
The vulnerability is an improper access control issue (CWE-1274) in the Chassis Management Board's boot chain implementation. The Cosmo board lacks secure boot protections and does not verify the integrity of firmware before boot or after upgrades. An attacker with physical access can modify the board firmware via JTAG interface or through the unverified firmware upgrade mechanism (accessible with root privileges). Once modified, the firmware changes are persistent and undetectable by the appliance or end user, allowing an attacker to control tamper events, USB access, and the LCD display. The attack vector is physical; patches are available in versions 13.6.12 (LTS) and 13.9.0 (STS).
Affected products
- Entrust nShield Connect XC through 13.6.11
- Entrust nShield 5c through 13.6.11
- Entrust nShield HSMi through 13.6.11, or 13.7
Timeline
- 2025-09-22: disclosed: Vulnerability initially disclosed via Google Security Research advisory GHSA-6q4x-m86j-gfwj
- 2025-12-02: advisory: CVE-2025-59694 published to NVD and GitHub Advisory Database
- 2025-09-22: patched: Patches available: version 13.6.12 (LTS) and 13.9.0 (STS)