Junglewise Threat Intelligence

CVE-2025-59704: Entrust nShield HSM BIOS access without password authentication

CVE-2025-59704 · Severity: medium · CVSS 4.6 · Published 2025-12-02

Technologies: Entrust Nshield Hsmi, Entrust nShield Connect XC, Entrust Nshield 5c. Vendors: Entrust.

Executive brief

Entrust nShield HSMs (Connect XC, 5c, and HSMi) are hardware security modules that protect cryptographic keys and execute secure operations for enterprises. An attacker with physical access to the device can bypass BIOS authentication entirely and gain unauthorized access to the BIOS menu, potentially allowing firmware modification or other system-level attacks. This undermines the core security guarantees of the hardware and could lead to complete device compromise.

Technical details

The vulnerability is an improper authentication flaw (CWE-287) in the BIOS menu access control of affected nShield HSM models. The BIOS menu is accessible without any password or authentication mechanism, allowing an attacker with physical access to the device to directly manipulate firmware settings. This is compounded by related vulnerabilities in the boot chain (CVE-2025-59693, CVE-2025-59694, CVE-2025-59695, CVE-2025-59696) that enable firmware modification without triggering tamper protection. The attack requires physical access to the device but no special privileges or user interaction. Patches are available in nShield versions 13.6.12 (LTS) and 13.9.0 (STS).

Affected products

  • Entrust nShield Connect XC through 13.6.11; 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
  • Entrust nShield 5c through 13.6.11; 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)
  • Entrust nShield HSMi through 13.6.11; 13.7 (patched in 13.6.12 LTS and 13.9.0 STS)

Timeline

  • 2025-12-02: disclosed: CVE-2025-59704 published
  • 2025: patched: Patches released in nShield 13.6.12 (LTS) and 13.9.0 (STS)

References

Related threats