Database/Firmware, BMC & network fabric
Entrust nShield HSM: BIOS setup menu has no password, so physical access allows boot configuration changes
Impact
The BIOS setup menu on these HSM appliances is not password protected, so anyone standing in front of the unit can enter setup and alter boot configuration. An HSM's value rests entirely on its tamper boundary and a controlled boot path, and it typically holds the signing and encryption keys the rest of the fleet depends on, so an unrestricted setup menu weakens the integrity assurance the appliance is bought for. The record claims integrity impact only, with no confidentiality or availability effect. Affected through 13.6.11 and 13.7; fixed in 13.6.12 (LTS) and 13.9.0 (STS).
Who can reach it
Physical access to the appliance in the rack, no credentials required. Not reachable over the network or the management VLAN.
What to do
Upgrade appliance firmware to 13.6.12 (LTS) or 13.9.0 (STS) per the Entrust September 2025 advisory. The HSM is out of service during the upgrade, so run it against one member of the HSM set at a time. Until then the mitigation is the physical control that was already assumed: cage and rack locks plus tamper inspection on the units.
References
Related entries
- AMD Secure Processor TEE SOC driver - SR-IOV GFX firmware load command: A malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FWCVE-2025-66664 · AMD Secure Processor TEE SOC driver - SR-IOV GFX firmware load commandMedium
- Intel TDX Guest software: incorrect calculation allows privilege escalation inside the trust domainCVE-2026-20763 · Intel TDX Guest software (guest-side TDX components before 0.3.1)Medium
- Intel TDX Guest software: incorrect comparison lets a privileged local actor escalate inside a TD guestCVE-2026-20765 · Intel TDX Guest software (ring 3 user applications)Medium
- Dell OpenManage Enterprise: low-privileged user can inject script into the console and expose informationCVE-2026-54793 · Dell OpenManage Enterprise (web console cross-site scripting)Medium
- Lenovo XClarity Controller: Backup/restore password written to an internal XCC log bufferCVE-2021-3473 · Lenovo XClarity ControllerMedium
- Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000: The patched ME firmware doesCVE-2017-5698 · Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.