Junglewise Threat Intelligence

CVE-2025-59702: Entrust nShield HSM tamper event falsification via physical access

CVE-2025-59702 · Severity: high · CVSS 7.2 · Published 2025-12-02

Technologies: Entrust Nshield Hsmi, Entrust nShield Connect XC, Entrust Nshield 5c. Vendors: Entrust.

Executive brief

Entrust's nShield HSM appliances are used to protect cryptographic keys and secure operations for financial institutions and enterprises. A physically proximate attacker with elevated privileges can falsify or erase tamper event logs by accessing internal hardware components without triggering security alarms, potentially hiding unauthorized access or modifications to the device.

Technical details

This vulnerability (CWE-203: Observable Discrepancy) allows an attacker with physical access and elevated privileges to modify the unencrypted tamper event log stored on an I2C EEPROM on the Cosmo board. An attacker can access the JTAG connector on the device or use root access via firmware upgrades to edit or clear the tamper log without detection. The vulnerability requires physical proximity and elevated privileges but poses a critical integrity risk, as it enables persistent, undetectable modification of security logs that are meant to alert operators to tampering. Patches are available in versions 13.6.12 (LTS) and 13.9.0 (STS).

Affected products

  • Entrust nShield Connect XC through 13.6.11; patched in 13.6.12 (LTS) and 13.9.0 (STS)
  • Entrust nShield 5c through 13.6.11; patched in 13.6.12 (LTS) and 13.9.0 (STS)
  • Entrust nShield HSMi through 13.6.11, or 13.7; patched in 13.6.12 (LTS) and 13.9.0 (STS)

Timeline

  • 2025-12-02: disclosed
  • 2025-09-22: patched: Patches available in versions 13.6.12 (LTS) and 13.9.0 (STS)

References

Related threats