CVE-2025-59700 Details
Description
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection).
A vulnerability exists in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allowing a physically proximate attacker with root access to modify the Recovery Partition. This issue arises from inadequate integrity protection, enabling unauthorized alterations that could persist across factory resets.
Users can update to Entrust nShield versions 13.6.12 or 13.9.0, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| entrust nshield 5c firmware | < 13.6.12 >= 13.7, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield 5c | All versions |
CPE
Remediation
| |
| entrust nshield hsmi firmware | < 13.6.12 >= 13.7, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield hsmi | All versions |
CPE
Remediation
| |
| entrust nshield connect xc base firmware | < 13.6.12 >= 13.7, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield connect xc base | All versions |
CPE
Remediation
| |
| entrust nshield connect xc mid firmware | < 13.6.12 >= 13.7, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield connect xc mid | All versions |
CPE
Remediation
| |
| entrust nshield connect xc high firmware | < 13.6.12 >= 13.7, < 13.9.0 |
CPE
Remediation
| |
| entrust nshield connect xc high | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 26, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jan 6, 2026 | CVE Modified | CISA-ADP |
| Dec 8, 2025 | Initial Analysis | [email protected] |
| Dec 3, 2025 | CVE Modified | CISA-ADP |
| Dec 2, 2025 | New CVE Received | [email protected] |