You claim the contents of memory are encrypted with a 4-digit PIN; I'm telling you this is false, they're encrypted with a 256-bit key held inside the HSM [0]. It matters because a 4-digit AES key is indeed trivial to crack but a 256-bit key is not.
I'm not sure you understand what an HSM is. It doesn't help to "emulate" one. An HSM performs cryptographic operations under certain conditions (such as correct PIN entry) using internally stored keys. The whole point is that you can't get the keys out, only use them. If you had another HSM, or a logical model of one, it wouldn't contain the right keys.
Certainly as engineered systems, it's possible for HSMs to contain vulnerabilities, but getting the key out of an HSM is a much more sophisticated task than cracking a keyspace of just 10,000 possibilities. Possible, maybe.
[0]http://www.apple.com/business/docs/iOS_Security_Guide.pdf