GPU VulnDB

Database/Firmware, BMC & network fabric

Entrust nShield HSM: BIOS setup menu has no password, so physical access allows boot configuration changes

CVE-2025-59704Firmware, BMC & network fabriccurated

Impact

The BIOS setup menu on these HSM appliances is not password protected, so anyone standing in front of the unit can enter setup and alter boot configuration. An HSM's value rests entirely on its tamper boundary and a controlled boot path, and it typically holds the signing and encryption keys the rest of the fleet depends on, so an unrestricted setup menu weakens the integrity assurance the appliance is bought for. The record claims integrity impact only, with no confidentiality or availability effect. Affected through 13.6.11 and 13.7; fixed in 13.6.12 (LTS) and 13.9.0 (STS).

Who can reach it

Physical access to the appliance in the rack, no credentials required. Not reachable over the network or the management VLAN.

What to do

Upgrade appliance firmware to 13.6.12 (LTS) or 13.9.0 (STS) per the Entrust September 2025 advisory. The HSM is out of service during the upgrade, so run it against one member of the HSM set at a time. Until then the mitigation is the physical control that was already assumed: cage and rack locks plus tamper inspection on the units.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.