External risk intelligence

Entrust nShield Firmware OS Root Privilege Escalation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-59695

The vulnerability affects Hardware Security Modules (HSMs), which are specialized security appliances designed to be deployed in isolated, highly restricted internal data center environments. They are not intended to be exposed to the public internet and require significant internal privilege to exploit.

Missing Authentication

Entrust Nshield 5c Firmware

before 13.6.1213.7.3 to before 13.9.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Entrust nShield hardware security modules that could allow an authenticated user with root access to alter the device's firmware without proper authentication. This could potentially compromise the integrity and security functions of these critical devices. The main concern is confirming relevance and exposure to this threat.

  • Unauthenticated firmware alteration possible on hardware security devices.
  • Affects critical components managing sensitive cryptographic operations.
  • Confirm device relevance and exposure; assess potential security impact.

Attack Path

How an attacker could exploit the issue

An attacker with existing operating system root access can modify the firmware on the Chassis Management Board. This firmware alteration, known as F04, bypasses authentication and can lead to a compromise of the hardware security module.

  • Requires OS root access.
  • Alters device firmware without authentication.
  • Allows critical system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker with OS root access to modify the firmware on a device's Chassis Management Board. This could potentially impact the security functions performed by the hardware, though no specific data types or PII are identified as being at risk.

  • Hardware Security Module (HSM) firmware.
  • Alteration of firmware without authentication.
  • Compromise of hardware security functions.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Entrust nShield hardware and its operating firmware should lead the response. The first practical step involves identifying all deployed nShield devices, verifying their network exposure and business criticality, and confirming ownership. Following this, a risk-based remediation plan can be developed, potentially involving vendor coordination for firmware updates.

  • Hardware and firmware teams own the issue.
  • Verify device exposure and criticality.
  • Plan firmware update according to risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What are Entrust nShield HSMs used for?

Entrust nShield Hardware Security Modules are specialized security appliances. Organizations use them as a root of trust to manage, protect, and process sensitive cryptographic keys and digital certificates. They are central to securing internal data, transactions, and identity infrastructure.

What is the vulnerability in CVE-2025-59695?

This is a missing authentication vulnerability, categorized as CWE-306. It specifically impacts the Chassis Management Board firmware. If a user already has OS-level root access, they can modify this firmware without providing the necessary authentication tokens, which would otherwise be required to protect such a critical system component.

Can I trigger this flaw without root access?

No. The vulnerability requires an attacker to already possess root-level access to the device's operating system. If you do not have root access, this specific firmware modification path is not available. Normal user activity or standard network interactions alone cannot trigger this bug.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that this threat is very unlikely for most because these modules are designed for isolated, internal data center environments. They are not intended for public internet exposure. Risk is primarily localized to internal environments where an attacker has already gained the high-level system privileges mentioned.

How do I start responding to this advisory?

Begin by identifying all Entrust nShield hardware in your environment and confirming the current firmware versions installed. Determine if any devices deviate from the patched versions (13.6.12 or 13.9.0). Coordinate with your hardware and infrastructure security teams to prioritize updates for those systems while confirming their isolation from unauthorized network access.

References