Junglewise Threat Intelligence

CVE-2025-59701: Entrust nShield unencrypted SSD storage access

CVE-2025-59701 · Severity: medium · CVSS 4.1 · Published 2025-12-02

Technologies: Entrust Nshield Hsmi, Entrust nShield Connect XC, Entrust Nshield 5c. Vendors: Entrust.

Executive brief

Entrust nShield hardware security modules (HSMs) are appliances used to store and manage cryptographic keys for organizations. A physically proximate attacker with elevated privileges can directly access and modify the unencrypted SSD, potentially exposing or tampering with sensitive key material and system data stored on the device.

Technical details

This vulnerability is a cleartext storage issue (CWE-312) affecting the Appliance SSD in nShield HSMs. The SSD contents are stored unencrypted, allowing an attacker with physical access and elevated privileges to read and modify the storage directly. The attack requires physical proximity and elevated privileges on the device. An attacker can extract sensitive key material, configuration data, or inject malicious modifications. Patches are available in version 13.6.12 (LTS) and 13.9.0 (STS); affected versions include 13.6.11 and earlier, and 13.7.

Affected products

  • Entrust nShield Connect XC through 13.6.11, 13.7 (patched in 13.6.12, 13.9.0)
  • Entrust nShield 5c through 13.6.11, 13.7 (patched in 13.6.12, 13.9.0)
  • Entrust nShield HSMi through 13.6.11, 13.7 (patched in 13.6.12, 13.9.0)

Timeline

  • 2025-12-02: disclosed
  • 2025-09-22: patched: Patches available in version 13.6.12 (LTS) and 13.9.0 (STS)

References

Related threats