CVE-2025-59694 Details
Description
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the attacker must modify the firmware via JTAG or perform an upgrade to the chassis management board firmware. This is called F03.
A vulnerability exists in the Chassis Management Board of Entrust nShield Connect XC, nShield 5c, and nShield HSMi, affecting versions through 13.6.11 or 13.7. This vulnerability allows a physically proximate attacker to persistently modify firmware and disrupt the appliance's boot process, which is insecurely configured. Exploitation requires physical access to the device to modify the firmware via JTAG or to perform an upgrade to the chassis management board firmware.
Users can upgrade to Entrust nShield versions 13.6.12 or 13.9.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1274 | Improper Access Control for Volatile Memory Containing Boot Code | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| entrust nshield 5c firmware | < 13.6.12 >= 13.7.3, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield 5c | All versions |
CPE
Remediation
| |
| entrust nshield hsmi firmware | < 13.6.12 >= 13.7.3, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield hsmi | All versions |
CPE
Remediation
| |
| entrust nshield connect xc base firmware | < 13.6.12 >= 13.7.3, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield connect xc base | All versions |
CPE
Remediation
| |
| entrust nshield connect xc mid firmware | < 13.6.12 >= 13.7.3, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield connect xc mid | All versions |
CPE
Remediation
| |
| entrust nshield connect xc high firmware | < 13.6.12 >= 13.7.3, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield connect xc high | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | CVE Modified | CISA-ADP |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Dec 15, 2025 | Initial Analysis | [email protected] |
| Dec 3, 2025 | CVE Modified | CISA-ADP |
| Dec 2, 2025 | New CVE Received | [email protected] |