Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.
https://www.entrust.com/use-case/why-use-an-hsm
https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj