CVE-2025-59705

MEDIUM

Entrust nShield HSM <13.6.12 - Physically Proximate Privilege Escalation via USB Interface

Title source: llm
STIX 2.1

Description

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.

Scores

CVSS v3 6.8
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (5)
entrust/nshield_5c_firmware < 13.6.12
entrust/nshield_connect_xc_base_firmware < 13.6.12
entrust/nshield_connect_xc_high_firmware < 13.6.12
entrust/nshield_connect_xc_mid_firmware < 13.6.12
entrust/nshield_hsmi_firmware < 13.6.12
Published Dec 02, 2025
Tracked Since Feb 18, 2026