External risk intelligence

Entrust nShield Physical Tamper F14 Attack Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-59703

The vulnerability requires physical proximity to the hardware appliance, including the removal of tamper labels and screws. It is not reachable over a network or the public internet, as it necessitates direct, hands-on physical access to the device.

Entrust Nshield 5c Firmware

before 13.6.1213.7 to before 13.9.0

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in Entrust nShield hardware security modules, specifically affecting devices through certain firmware versions. The issue allows an attacker with physical access to tamper with the appliance without detection, potentially compromising its security functions. While the vulnerability requires physical access, which limits its reach, it could have significant implications for the security of systems relying on these devices for key management and cryptographic operations.

  • Physical access allows undetected tampering.
  • Protects cryptographic keys and sensitive operations.
  • Confirm relevance and assess physical security controls.

Attack Path

How an attacker could exploit the issue

An attacker with physical access to the hardware can circumvent security measures by removing tamper labels and screws without detection. This "F14 attack" allows access to internal components, potentially leading to compromised data protection.

  • Requires physical proximity to the device.
  • Involves removing tamper evidence.
  • Risk of internal component access.

Live Threat

Current exploitation, exposure, and threat context

A physically proximate attacker could gain access to the internal components of the Entrust nShield appliance by removing tamper labels and screws. This attack, known as F14, could expose sensitive information or allow unauthorized modifications when supported by the advisory's conditions.

  • Sensitive hardware components.
  • Physical tampering with the appliance.
  • Potential compromise of cryptographic operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Entrust nShield hardware security modules (HSMs). Given the physical access requirement, ownership likely resides with teams managing physical infrastructure and critical security appliances, such as infrastructure or security operations teams. The first step is to inventory all nShield devices, confirm their physical security, and verify if they are running a vulnerable firmware version.

  • Infrastructure or security operations teams own remediation.
  • Verify physical security and firmware versions.
  • Plan firmware updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is an Entrust nShield HSM?

Entrust nShield Hardware Security Modules (HSMs) are specialized, hardened appliances designed to safeguard cryptographic keys and perform sensitive operations like digital signing or encryption. These devices act as a root of trust for organizations, ensuring that critical keys remain protected within highly secure, tamper-resistant hardware environments.

What does CWE-284 mean for CVE-2025-59703?

CWE-284 relates to improper access control. In the context of this CVE, it describes a weakness where the appliance fails to prevent unauthorized access to its internal physical components. An attacker can circumvent the device's protective mechanisms, effectively bypassing the security controls intended to keep the internal hardware inaccessible to those without proper authorization.

How is this physical tamper attack triggered?

An attacker must have direct physical proximity to the device to perform this action, known as an F14 attack. It requires the manual removal of tamper-evident labels and the device's fixing screws to expose the internal components. It is important to note that this vulnerability cannot be triggered remotely; it does not occur via network connections, software commands, or any digital interaction with the system's firmware or operating logic.

Is my device at risk if it is in a locked data center?

Halo Surface Signal classifies this as very unlikely for internet-based threats because the vulnerability necessitates direct, hands-on physical access. While the risk is low for network-only attackers, you should still evaluate your physical access controls. If your facility's security allows someone to sit at the rack and dismantle the hardware, the device remains potentially susceptible to this specific physical bypass method.

What should I do if I use nShield hardware?

Start by identifying all nShield units in your environment and checking their current firmware versions against the advisory’s list of affected versions. Verify the physical integrity of these units to ensure no tampering has occurred. Consult the official Entrust documentation to plan a maintenance window for upgrading to the patched firmware versions, which restore the intended levels of physical protection.

References