Executive brief
Entrust nShield HSM devices (including Connect XC, 5c, and HSMi models) use a hardware security module to protect cryptographic keys for enterprise applications. An attacker with physical access can bypass security controls by connecting to a pin during device boot to enable the USB interface, then use keyboard input during startup to gain root access to the appliance. This allows complete compromise of the device without triggering tamper alarms or leaving visible evidence.
Technical details
This vulnerability comprises multiple related privilege escalation issues (F01-F05) in the nShield boot chain and firmware protection mechanisms. F01 specifically allows a physically proximate attacker to enable the USB interface by connecting to an exposed pin during system boot, which does not trigger tamper events. Once USB is enabled, an attacker can attach a keyboard and repeatedly interrupt the GRUB boot process to gain an interactive shell, leading to root access. The root cause is insufficient physical security controls and the lack of secure boot verification. Attack requires physical proximity to the device during boot sequence. Patches are available in 13.6.12 (LTS) and 13.9.0 (STS).
Affected products
- Entrust nShield Connect XC through 13.6.11 or 13.7 (patched in 13.6.12 LTS, 13.9.0 STS)
- Entrust nShield 5c through 13.6.11 or 13.7 (patched in 13.6.12 LTS, 13.9.0 STS)
- Entrust nShield HSMi through 13.6.11 or 13.7 (patched in 13.6.12 LTS, 13.9.0 STS)
Timeline
- 2025-09-22: disclosed: Google Security Research advisory published
- 2025-12-02: disclosed: CVE-2025-59705 published on NVD
- 2025-09-22: patched: Patches available: v13.6.12 (LTS) and v13.9.0 (STS)