Entrust nShield Connect XC - Multiple Vulnerabilities Leading to Insecure Boot Chain Protections
HighCVE-2025-59705 · Published Sep 22, 2025 · updated Sep 23, 2025
### Summary The tested nShield Connect XC HSM appliance can be rooted and backdoored via physical attack vectors in less than 5 minutes without leaving visible traces or triggering tamper events. There are multiple ways to modify the appliance without leaving any traces. These modifications lead to persistent, undetectable, and unrecoverable compromise of the appliance. ### Vulnerability Listings #### F01 Cosmo: Front USB port can be enabled at any time including during boot without triggering a tamper event | CVE-2025-59705 #### Summary An attacker with physical access can enable USB access during boot. This can be used to gain root access to the appliance and subsequently persist on the device indefinitely and undetectably. This attack does not trigger a tamper event or any other protections, does not damage any components and does not leave any visible traces. #### Proof of Concept <img width="338" height="312" alt="Screenshot 2025-09-19 at 12 14 45 PM" src="https://github.com/user-attachments/assets/49bdfdac-5d79-4cb5-b41f-3796ac6ff560" /> <br> <img width="451" height="255" alt="Screenshot 2025-09-19 at 12 15 50 PM" src="https://github.com/user-attachments/assets/f3465616-...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Connect XC Product | < V13.6.12andv13.9.0 | V13.6.12andv13.9.0 |
Details and references
### Summary The tested nShield Connect XC HSM appliance can be rooted and backdoored via physical attack vectors in less than 5 minutes without leaving visible traces or triggering tamper events. There are multiple ways to modify the appliance without leaving any traces. These modifications lead to persistent, undetectable, and unrecoverable compromise of the appliance. ### Vulnerability Listings #### F01 Cosmo: Front USB port can be enabled at any time including during boot without triggering a tamper event | CVE-2025-59705 #### Summary An attacker with physical access can enable USB access during boot. This can be used to gain root access to the appliance and subsequently persist on the device indefinitely and undetectably. This attack does not trigger a tamper event or any other protections, does not damage any components and does not leave any visible traces. #### Proof of Concept <img width="338" height="312" alt="Screenshot 2025-09-19 at 12 14 45 PM" src="https://github.com/user-attachments/assets/49bdfdac-5d79-4cb5-b41f-3796ac6ff560" /> <br> <img width="451" height="255" alt="Screenshot 2025-09-19 at 12 15 50 PM" src="https://github.com/user-attachments/assets/f3465616-680b-48cd-8665-5cfa2fc6c7bd" /> </br> - Connect to the pin - Thin wires fit through multiple holes in the port, there are several ways to reach the pin (see red arrows in the image above). - The simplest way to make this attack repeatable is to take a robust wire that is still thin enough to fit through the holes, or a thin needle, and bend it into the right shape to reach the pin on a test device. - The correct insertion depth and orientation can then be marked on this basic tool after it has successfully been connected to the pin. - This tool can then be used on other devices of the same model. Both the USB port and the pin are on the same PCB, meaning that there might be small differences in the required insertion depth, but the tool will get very close by default and can then be adjusted. - More complex 3D-printed tools with micropositioning features can make this attack significantly faster and more reliable. - The connection to the correct pin can be tested with a multimeter. A successful connection shows 3.3V when the device is running and 0V when it is turned off or booting. It's connected to ground with a 10k pull-down resistor that can also be tested for and draws 62mA when powered while the device is off or booting. - The front screws provide a reliable connection to ground. - Pull the pin up to 3.3V (In our attempts, the PSU shows 62mA being drawn if the connection is successful) - Plug in a keyboard to the front USB port - Boot the HSM - Hit c repeatedly on boot (right after the HSM beeps) to enter the grub shell - Press enter to start a new prompt - Type "reboot" and press enter - The HSM will beep again at POST, you can repeat the steps above indefinitely. #### F02 Cosmo: Firmware and storage can be read and modified via JTAG | CVE-2025-59693 #### Summary An attacker with physical access (enabled by F14) can open the chassis and access the JTAG connector located on the Cosmo board to read and modify the firmware of the ARM SoC on the board as well as modify or clear the tamper log stored on the attached EEPROM (see F05). This enables an attacker to open the chassis without leaving any traces, and thereby allows access to other internals such as the unencrypted SSD. #### Further Analysis No protections provided by the ARM SoC are active, JTAG allows access to internal flash, sram, etc. This allows an attacker to modify the firmware without any restrictions. The cosmo board exposes a standard JTAG header. #### F03 Cosmo: Unprotected boot chain | CVE-2025-59694 #### Summary An attacker with access to Cosmo can persistently modify firmware, there are no protections such as secure boot in place. An attacker with control over Cosmo can influence the appliance boot process,
- Severity from
- GitHub (reviewed advisory)
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 272025 | Python - Zip64 Locator Offset Vulnerability | Medium | No fix yet |
| Sep 82025 | FFmpeg - Heap-buffer-overflow write in jpeg2000dec | High | No fix yet |
| Sep 82025 | ChatGPT Agent - XSS on file://home/oai/redirect.html | Medium | No fix yet |
| Aug 252025 | SQLite: Integer truncation in findOrCreateAggInfoColumn | High | 3.50.2 |
| Aug 182025 | OpenAI Operator - Click on arbitrary origin by TOCTOU attack | High | No fix yet |
| Aug 152025 | SQLite - Integer Overflow in FTS5 Extension | Medium | 3.50.3 |