CVE-2025-59705

MEDIUM

Entrust Nshield 5C Firmware < 13.6.12 - Improper Privilege Management

Title source: rule
STIX 2.1

Description

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.

Scores

CVSS v3 6.8
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (5)
entrust/nshield_5c_firmware < 13.6.12
entrust/nshield_connect_xc_base_firmware < 13.6.12
entrust/nshield_connect_xc_high_firmware < 13.6.12
entrust/nshield_connect_xc_mid_firmware < 13.6.12
entrust/nshield_hsmi_firmware < 13.6.12
Published Dec 02, 2025
Tracked Since Feb 18, 2026