Executive brief
Entrust nShield HSMs are cryptographic appliances used to secure and manage encryption keys for organizations. A physically proximate attacker can open these devices without triggering tamper detection, access internal components including firmware storage, and persistently modify the device to gain unauthorized access to protected cryptographic keys. This could allow an attacker to compromise the entire cryptographic infrastructure protected by the HSM.
Technical details
This vulnerability chain encompasses multiple physical and firmware-level attacks (F01–F05) on Entrust nShield HSM appliances. The root cause is inadequate physical tamper detection and lack of secure boot protections. An attacker can remove the tamper label and screws (F14 attack) without triggering events, then exploit multiple attack paths: enabling the front USB port during boot to gain root access (F01), reading/modifying firmware via JTAG (F02), loading unsigned firmware due to absent secure boot (F03), modifying firmware via unverified upgrade mechanisms (F04), and tampering with the tamper event log itself (F05). Attack requires physical proximity to the device but no authentication or user interaction. Patches are available in versions 13.6.12 (LTS) and 13.9.0 (STS).
Affected products
- Entrust nShield Connect XC through 13.6.11 (patched in 13.6.12 LTS and 13.9.0 STS)
- Entrust nShield 5c through 13.6.11 (patched in 13.6.12 LTS and 13.9.0 STS)
- Entrust nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
Timeline
- 2025-09-22: disclosed: Google Security Research advisory published (GHSA-6q4x-m86j-gfwj)
- 2025-12-02: advisory: CVE-2025-59703 published to NVD and GitHub Advisory Database
- 2025: patched: Patch available in nShield 13.6.12 (LTS) and 13.9.0 (STS)