Executive brief
Entrust nShield hardware security modules (HSMs) are appliances that generate and protect cryptographic keys for enterprise use. An attacker with physical access to an HSM can modify or erase its tamper event logs through the chassis management board, allowing them to hide evidence of intrusions or physical tampering without triggering security alerts.
Technical details
This vulnerability (CVE-2025-59696) stems from inadequate physical access controls on the Cosmo management board—specifically, the unencrypted, unprotected tamper event log stored on an I2C EEPROM. An attacker with physical access can read or modify the tamper log contents directly via JTAG (as described in CVE-2025-59693) or through root access on the Cosmo board. The log is stored in plaintext without authentication, signature, or encryption protections. The vulnerability requires low privilege and physical proximity; no user interaction is needed. An attacker can thus cover tracks of physical intrusion, firmware modification, or chassis opening. Patches are available in versions 13.6.12 (LTS) and 13.9.0 (STS).
Affected products
- Entrust nShield Connect XC through 13.6.11; 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
- Entrust nShield 5c through 13.6.11; 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
- Entrust nShield HSMi through 13.6.11; 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
Timeline
- 2025-09-22: disclosed: Initial disclosure of multiple nShield vulnerabilities including tamper event modification (CVE-2025-59696)
- 2025-12-02: advisory: CVE-2025-59696 published to NVD
- 2025-12-02: patched: Patches available in nShield 13.6.12 (LTS) and 13.9.0 (STS)