Entrust nShield Products BIOS Access Vulnerability

Vulnerability

A vulnerability in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows an attacker to access the BIOS menu, as it is not password protected. This vulnerability can be exploited by enabling USB access during boot, which can be done physically on the nShield HSM.

Impact

Exploitation of this vulnerability allows unauthorized access to the BIOS setup, where security-relevant settings can be modified. This includes options that grant highly privileged access to the system.

Reproduction

The vulnerability can be reproduced by physically accessing the HSM and enabling the front USB port during boot. This can be done by inserting a thin wire or needle through the front USB port to connect to a pin that activates the USB port. Once the USB port is enabled, the HSM can be booted up. By pressing 'c' repeatedly after the HSM beeps, access to the GRUB bootloader can be gained. From there, kernel parameters can be modified to initiate a root shell on boot, or to edit the recovery partition, among other actions.

Remediation

Users can update to Entrust nShield versions 13.6.12 or 13.9.0, where this vulnerability has been fixed.

Added: Dec 2, 2025, 4:21 PM
Updated: Dec 2, 2025, 5:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
7.7
relevance
1.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.