CVE-2025-59703
9.1Entrust · nShield Connect / nShield 5c / nShield HSMi
A physical tamper vulnerability in Entrust nShield HSM appliances allows physically proximate attackers to bypass tamper detection mechanisms and access internal components.
Executive summary
A physical security vulnerability in Entrust nShield HSM appliances allows attackers with physical access to bypass tamper-evident controls and potentially compromise sensitive cryptographic material.
Vulnerability
This vulnerability, known as an "F14 attack," involves the manipulation of physical security features such as tamper labels and screws. A physically proximate attacker can gain access to internal appliance components without triggering tamper evidence.
Business impact
Compromise of a Hardware Security Module (HSM) can lead to the exposure of root cryptographic keys, undermining the entire security architecture of the organization. Given the CVSS score of 9.1, this represents a critical risk to the integrity of encrypted data and digital signatures.
Remediation
Immediate Action: Review the Entrust security advisory and implement the recommended physical security enhancements or configuration changes to mitigate the risk of unauthorized physical access.
Proactive Monitoring: Implement strict physical access controls, including surveillance of server rooms and tamper-evident auditing of all HSM hardware.
Compensating Controls: Ensure that HSMs are housed in locked, monitored, and physically secure racks to prevent the proximity required for this attack.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing affected Entrust nShield appliances must prioritize physical site security and verify their hardware against the vendor's guidance. Since this is a physical attack vector, the primary mitigation involves strictly controlling physical access to the appliances and following vendor-provided hardening procedures.