Entrust nShield Products Recovery Partition Modification Vulnerability

Vulnerability

A vulnerability exists in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allowing a physically proximate attacker with root access to modify the Recovery Partition. This issue arises from inadequate integrity protection, enabling unauthorized alterations that could persist across factory resets.

Impact

Exploitation of this vulnerability allows for unauthorized modifications to the recovery partition, which can be used to maintain persistence on the device even after a factory reset.

Reproduction

To reproduce this vulnerability, gain root access to the affected nShield appliance. This can be achieved by enabling the front USB port during boot, connecting a keyboard, and accessing the GRUB bootloader. Once in the GRUB shell, add 'init=/bin/sh' to the kernel parameters and boot the device. After gaining access to the root shell, mount the recovery partition and make the desired modifications.

Remediation

Users can update to Entrust nShield versions 13.6.12 or 13.9.0, where this vulnerability has been addressed.

Added: Dec 2, 2025, 3:22 PM
Updated: Dec 2, 2025, 5:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
3.0
remediation
7.7
relevance
1.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.