Junglewise Threat Intelligence

CVE-2025-59705: Entrust nShield HSM USB interface privilege escalation via physical access

CVE-2025-59705 · Severity: medium · CVSS 6.8 · Published 2025-12-02

Technologies: Entrust Nshield Hsmi, Entrust nShield Connect XC, Entrust Nshield 5c. Vendors: Entrust.

Executive brief

Entrust nShield HSM devices (including Connect XC, 5c, and HSMi models) use a hardware security module to protect cryptographic keys for enterprise applications. An attacker with physical access can bypass security controls by connecting to a pin during device boot to enable the USB interface, then use keyboard input during startup to gain root access to the appliance. This allows complete compromise of the device without triggering tamper alarms or leaving visible evidence.

Technical details

This vulnerability comprises multiple related privilege escalation issues (F01-F05) in the nShield boot chain and firmware protection mechanisms. F01 specifically allows a physically proximate attacker to enable the USB interface by connecting to an exposed pin during system boot, which does not trigger tamper events. Once USB is enabled, an attacker can attach a keyboard and repeatedly interrupt the GRUB boot process to gain an interactive shell, leading to root access. The root cause is insufficient physical security controls and the lack of secure boot verification. Attack requires physical proximity to the device during boot sequence. Patches are available in 13.6.12 (LTS) and 13.9.0 (STS).

Affected products

  • Entrust nShield Connect XC through 13.6.11 or 13.7 (patched in 13.6.12 LTS, 13.9.0 STS)
  • Entrust nShield 5c through 13.6.11 or 13.7 (patched in 13.6.12 LTS, 13.9.0 STS)
  • Entrust nShield HSMi through 13.6.11 or 13.7 (patched in 13.6.12 LTS, 13.9.0 STS)

Timeline

  • 2025-09-22: disclosed: Google Security Research advisory published
  • 2025-12-02: disclosed: CVE-2025-59705 published on NVD
  • 2025-09-22: patched: Patches available: v13.6.12 (LTS) and v13.9.0 (STS)

References

Related threats