Description
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
Published: 2025-12-02
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 15 Dec 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Entrust nshield 5c Firmware
Entrust nshield Connect Xc Base
Entrust nshield Connect Xc Base Firmware
Entrust nshield Connect Xc High
Entrust nshield Connect Xc High Firmware
Entrust nshield Connect Xc Mid
Entrust nshield Connect Xc Mid Firmware
Entrust nshield Hsmi Firmware
CPEs cpe:2.3:h:entrust:nshield_5c:-:*:*:*:*:*:*:*
cpe:2.3:h:entrust:nshield_connect_xc_base:-:*:*:*:*:*:*:*
cpe:2.3:h:entrust:nshield_connect_xc_high:-:*:*:*:*:*:*:*
cpe:2.3:h:entrust:nshield_connect_xc_mid:-:*:*:*:*:*:*:*
cpe:2.3:h:entrust:nshield_hsmi:-:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_5c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_connect_xc_base_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_connect_xc_high_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_connect_xc_mid_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_hsmi_firmware:*:*:*:*:*:*:*:*
Vendors & Products Entrust nshield 5c Firmware
Entrust nshield Connect Xc Base
Entrust nshield Connect Xc Base Firmware
Entrust nshield Connect Xc High
Entrust nshield Connect Xc High Firmware
Entrust nshield Connect Xc Mid
Entrust nshield Connect Xc Mid Firmware
Entrust nshield Hsmi Firmware

Thu, 04 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Entrust
Entrust nshield 5c
Entrust nshield Connect Xc
Entrust nshield Hsmi
Vendors & Products Entrust
Entrust nshield 5c
Entrust nshield Connect Xc
Entrust nshield Hsmi

Tue, 02 Dec 2025 14:45:00 +0000

Type Values Removed Values Added
Description Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
References

Subscriptions

Entrust Nshield 5c Nshield 5c Firmware Nshield Connect Xc Nshield Connect Xc Base Nshield Connect Xc Base Firmware Nshield Connect Xc High Nshield Connect Xc High Firmware Nshield Connect Xc Mid Nshield Connect Xc Mid Firmware Nshield Hsmi Nshield Hsmi Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-04T17:54:55.437Z

Reserved: 2025-09-18T00:00:00.000Z

Link: CVE-2025-59695

cve-icon Vulnrichment

Updated: 2025-12-04T17:54:45.761Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T15:15:55.010

Modified: 2025-12-15T13:35:53.217

Link: CVE-2025-59695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-04T16:49:00Z

Weaknesses