Executive brief
Entrust nShield hardware security modules (HSMs) are physical appliances used to protect cryptographic keys and perform sensitive security operations. A physically proximate attacker can exploit an end-of-life legacy bootloader to gain unauthorized access to the device, potentially compromising all keys and operations protected by the HSM.
Technical details
The vulnerability stems from an insecure implementation of the legacy bootloader (EOL) in nShield HSM devices, classified as incorrect security token generation (CWE-1270). An attacker with physical proximity to the device can exploit this bootloader to gain access, potentially leading to full device compromise. The attack vector is physical only, requiring no authentication or user interaction. Patches are available in nShield 13.6.12 (LTS) and 13.9.0 (STS). The broader security research indicates related issues including unprotected JTAG access, unverified firmware upgrades, and inadequate tamper detection mechanisms in the Cosmo board.
Affected products
- Entrust nShield Connect XC through 13.6.11 or 13.7
- Entrust nShield 5c through 13.6.11 or 13.7
- Entrust nShield HSMi through 13.6.11 or 13.7
Timeline
- 2025-12-02: disclosed: CVE-2025-59698 published in NVD
- 2025-12-02: patched: Patches released: 13.6.12 (LTS) and 13.9.0 (STS)