Junglewise Threat Intelligence

CVE-2025-59700: Entrust nShield HSM recovery partition integrity vulnerability

CVE-2025-59700 · Severity: low · CVSS 3.9 · Published 2025-12-02

Technologies: Entrust Nshield Hsmi, Entrust nShield Connect XC, Entrust Nshield 5c. Vendors: Entrust.

Executive brief

Entrust nShield HSMs are security appliances that protect and manage cryptographic keys for enterprises. A physically proximate attacker with root access can modify the device's Recovery Partition without detection due to missing integrity verification. While this requires both physical proximity and root privileges, successful exploitation could allow persistent, undetectable compromise of the HSM and the keys it protects.

Technical details

This vulnerability stems from insufficient verification of data authenticity (CWE-345) in the Recovery Partition of nShield HSM appliances. The Recovery Partition lacks integrity protection mechanisms, allowing an attacker with root access and physical proximity to modify its contents without detection. The attack vector is physical with high privilege requirements (root access). Successful exploitation enables persistent and undetectable modification of the Recovery Partition, potentially leading to compromised key management operations. Patches are available: version 13.6.12 (LTS) and 13.9.0 (STS) address this issue.

Affected products

  • Entrust nShield Connect XC through 13.6.11 or 13.7; patched in 13.6.12 (LTS) and 13.9.0 (STS)
  • Entrust nShield 5c through 13.6.11 or 13.7; patched in 13.6.12 (LTS) and 13.9.0 (STS)
  • Entrust nShield HSMi through 13.6.11 or 13.7; patched in 13.6.12 (LTS) and 13.9.0 (STS)

Timeline

  • 2025-12-02: disclosed

References

Related threats