CVE-2025-59703

9.1

Entrust · nShield Connect / nShield 5c / nShield HSMi

A physical tamper vulnerability in Entrust nShield HSM appliances allows physically proximate attackers to bypass tamper detection mechanisms and access internal components.

Executive summary

A physical security vulnerability in Entrust nShield HSM appliances allows attackers with physical access to bypass tamper-evident controls and potentially compromise sensitive cryptographic material.

Vulnerability

This vulnerability, known as an "F14 attack," involves the manipulation of physical security features such as tamper labels and screws. A physically proximate attacker can gain access to internal appliance components without triggering tamper evidence.

Business impact

Compromise of a Hardware Security Module (HSM) can lead to the exposure of root cryptographic keys, undermining the entire security architecture of the organization. Given the CVSS score of 9.1, this represents a critical risk to the integrity of encrypted data and digital signatures.

Remediation

Immediate Action: Review the Entrust security advisory and implement the recommended physical security enhancements or configuration changes to mitigate the risk of unauthorized physical access.

Proactive Monitoring: Implement strict physical access controls, including surveillance of server rooms and tamper-evident auditing of all HSM hardware.

Compensating Controls: Ensure that HSMs are housed in locked, monitored, and physically secure racks to prevent the proximity required for this attack.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing affected Entrust nShield appliances must prioritize physical site security and verify their hardware against the vendor's guidance. Since this is a physical attack vector, the primary mitigation involves strictly controlling physical access to the appliances and following vendor-provided hardening procedures.