CVE-2025-59695
critical · 9.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
9.8
CVSS
0.7%
EPSS (exploit prob.)
51st
EPSS percentile
2025-12-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-306
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| entrust | nshield_5c_firmware | < 13.6.12 |
| entrust | nshield_5c_firmware | >= 13.7.3, < 13.9.0 |
| entrust | nshield_5c | all versions |
| entrust | nshield_hsmi_firmware | < 13.6.12 |
| entrust | nshield_hsmi_firmware | >= 13.7.3, < 13.9.0 |
| entrust | nshield_hsmi | all versions |
| entrust | nshield_connect_xc_base_firmware | < 13.6.12 |
| entrust | nshield_connect_xc_base_firmware | >= 13.7.3, < 13.9.0 |
| entrust | nshield_connect_xc_base | all versions |
| entrust | nshield_connect_xc_mid_firmware | < 13.6.12 |
| entrust | nshield_connect_xc_mid_firmware | >= 13.7.3, < 13.9.0 |
| entrust | nshield_connect_xc_mid | all versions |
| entrust | nshield_connect_xc_high_firmware | < 13.6.12 |
| entrust | nshield_connect_xc_high_firmware | >= 13.7.3, < 13.9.0 |
| entrust | nshield_connect_xc_high | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-59695