← Back

CVE-2025-59694

nvd nist
Published: Dec 2, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the attacker must modify the firmware via JTAG or perform an upgrade to the chassis management board firmware. This is called F03.

Affected (10)

5 products
Nshield 5c Firmware
Nshield Hsmi Firmware
Nshield Connect Xc Base Firmware
Nshield Connect Xc Mid Firmware
Nshield Connect Xc High Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Entrust
Before 13.6.12
From 13.7.3 to 13.9.0
Running on/withPlatform Versions
Entrust
Nshield 5c
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Entrust
Before 13.6.12
From 13.7.3 to 13.9.0
Running on/withPlatform Versions
Entrust
Nshield Hsmi
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Entrust
Before 13.6.12
From 13.7.3 to 13.9.0
Running on/withPlatform Versions
Entrust
Nshield Connect Xc Base
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Entrust
Before 13.6.12
From 13.7.3 to 13.9.0
Running on/withPlatform Versions
Entrust
Nshield Connect Xc Mid
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Entrust
Before 13.6.12
From 13.7.3 to 13.9.0
Running on/withPlatform Versions
Entrust
Nshield Connect Xc High
All versions

References (3)

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.