Vulnerability Description
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Entrust | Nshield 5C Firmware | < 13.6.12 |
| Entrust | Nshield 5C | - |
| Entrust | Nshield Hsmi Firmware | < 13.6.12 |
| Entrust | Nshield Hsmi | - |
| Entrust | Nshield Connect Xc Base Firmware | < 13.6.12 |
| Entrust | Nshield Connect Xc Base | - |
| Entrust | Nshield Connect Xc Mid Firmware | < 13.6.12 |
| Entrust | Nshield Connect Xc Mid | - |
| Entrust | Nshield Connect Xc High Firmware | < 13.6.12 |
| Entrust | Nshield Connect Xc High | - |
Related Weaknesses (CWE)
References
- https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gExploitThird Party Advisory
- https://www.entrust.com/use-case/why-use-an-hsmProduct
FAQ
What is CVE-2025-59695?
CVE-2025-59695 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is ...
How severe is CVE-2025-59695?
CVE-2025-59695 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-59695?
Check the references section above for vendor advisories and patch information. Affected products include: Entrust Nshield 5C Firmware, Entrust Nshield 5C, Entrust Nshield Hsmi Firmware, Entrust Nshield Hsmi, Entrust Nshield Connect Xc Base Firmware.