Executive brief
Entrust nShield HSMs are security appliances that protect and manage cryptographic keys for enterprises. A physically proximate attacker with root access can modify the device's Recovery Partition without detection due to missing integrity verification. While this requires both physical proximity and root privileges, successful exploitation could allow persistent, undetectable compromise of the HSM and the keys it protects.
Technical details
This vulnerability stems from insufficient verification of data authenticity (CWE-345) in the Recovery Partition of nShield HSM appliances. The Recovery Partition lacks integrity protection mechanisms, allowing an attacker with root access and physical proximity to modify its contents without detection. The attack vector is physical with high privilege requirements (root access). Successful exploitation enables persistent and undetectable modification of the Recovery Partition, potentially leading to compromised key management operations. Patches are available: version 13.6.12 (LTS) and 13.9.0 (STS) address this issue.
Affected products
- Entrust nShield Connect XC through 13.6.11 or 13.7; patched in 13.6.12 (LTS) and 13.9.0 (STS)
- Entrust nShield 5c through 13.6.11 or 13.7; patched in 13.6.12 (LTS) and 13.9.0 (STS)
- Entrust nShield HSMi through 13.6.11 or 13.7; patched in 13.6.12 (LTS) and 13.9.0 (STS)
Timeline
- 2025-12-02: disclosed