CVE Feed

    Dashboard / CVE / CVE-2025-59694

    CVE-2025-59694

    The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the attacker must modify the firmware via JTAG or perform an upgrade to the chassis management board firmware. This is called F03.

    Published:Dec 2, 2025
    Last Modified:Aug 26, 2026
    EPS:Dec 2, 2025
    EPSS Score:0.00275
    CVSS Score:6.8

    Affected Products

    Vendor
    Entrust
    Product
    Nshield 5c
    Vendor
    Entrust
    Product
    Nshield 5c Firmware
    Vendor
    Entrust
    Product
    Nshield Connect Xc
    Vendor
    Entrust
    Product
    Nshield Connect Xc Base
    Vendor
    Entrust
    Product
    Nshield Connect Xc Base Firmware
    Vendor
    Entrust
    Product
    Nshield Connect Xc High
    Vendor
    Entrust
    Product
    Nshield Connect Xc High Firmware
    Vendor
    Entrust
    Product
    Nshield Connect Xc Mid
    Vendor
    Entrust
    Product
    Nshield Connect Xc Mid Firmware
    Vendor
    Entrust
    Product
    Nshield Hsmi
    Vendor
    Entrust
    Product
    Nshield Hsmi Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High