Ledger researchers have discovered unauthenticated remote attacks on an HSM. They claim to have full control of the HSM and full access to the keys and secrets stored in it. The most disturbing part of the attack may be that the firmware update is persistent. There may be HSM deployed in critical infrastructure now with similar backdoors. The disruption caused by the disclosure of certain secret keys to the financial system of the target country would be very interesting for those seeking to wage cyberwar.”]
Source: https://hackercombat.com/major-vulnerabilities-in-hsms-discovered/