Junglewise Threat Intelligence

CVE-2025-59695: Entrust nShield Connect XC firmware modification without authentication

CVE-2025-59695 · Severity: critical · CVSS 9.8 · Published 2025-12-02

Technologies: Entrust Nshield Hsmi, Entrust nShield Connect XC, Entrust Nshield 5c. Vendors: Entrust.

Executive brief

Entrust nShield hardware security modules (HSMs) are cryptographic appliances that protect critical encryption keys used by financial institutions and enterprises. A vulnerability allows users with administrative access to modify the Chassis Management Board firmware without any authentication checks, potentially enabling persistent backdoors or disabling security protections on the device.

Technical details

This is a missing authentication vulnerability (CWE-306) in the Chassis Management Board (Cosmo) firmware upgrade mechanism on Entrust nShield appliances. An attacker with OS-level root access can invoke the cosmoupgrade utility to arbitrarily modify the Cosmo firmware without presenting any credentials. While the upgrade process validates the firmware version number and CRC, it does not authenticate the requester, allowing privileged local users to permanently compromise the device. Once root access is obtained (via separate physical or logical attack), this vulnerability enables persistent firmware backdoors that cannot be detected by the appliance or end-user, disable tamper event logging, and compromise the entire boot chain. Patches are available in nShield 13.6.12 (LTS) and 13.9.0 (STS).

Affected products

  • Entrust nShield Connect XC through 13.6.11, 13.7 (patched in 13.6.12, 13.9.0)
  • Entrust nShield 5c through 13.6.11, 13.7 (patched in 13.6.12, 13.9.0)
  • Entrust nShield HSMi through 13.6.11, 13.7 (patched in 13.6.12, 13.9.0)

Timeline

  • 2025-12-02: disclosed: CVE-2025-59695 published
  • 2025: patched: Patched in nShield 13.6.12 (LTS) and 13.9.0 (STS)

References

Related threats