{"id":"CVE-2025-59699","title":"Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root fi…","summary":"Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root fi…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-290"],"vendor":"entrust","product":"nshield_5c_firmware","affected":["nshield_5c_firmware < 13.6.12","nshield_5c_firmware >= 13.7, < 13.9.0","nshield_hsmi_firmware < 13.6.12","nshield_hsmi_firmware >= 13.7, < 13.9.0","nshield_connect_xc_base_firmware < 13.6.12","nshield_connect_xc_base_firmware >= 13.7, < 13.9.0","nshield_connect_xc_mid_firmware < 13.6.12","nshield_connect_xc_mid_firmware >= 13.7, < 13.9.0","nshield_connect_xc_high_firmware < 13.6.12","nshield_connect_xc_high_firmware >= 13.7, < 13.9.0"],"patched":["nshield_5c_firmware 13.9.0","nshield_hsmi_firmware 13.9.0","nshield_connect_xc_base_firmware 13.9.0","nshield_connect_xc_mid_firmware 13.9.0","nshield_connect_xc_high_firmware 13.9.0"],"published":"2025-12-02","updated":"2026-08-26","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-59699","references":[{"url":"https://github.com/advisories/GHSA-g9v7-h8x8-w5vw","label":"cve@mitre.org"},{"url":"https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj","label":"cve@mitre.org"},{"url":"https://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025","label":"cve@mitre.org"},{"url":"https://www.entrust.com/use-case/why-use-an-hsm","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00329,"epssPercentile":0.26199,"ingestedAt":"2026-08-26T16:46:30.148Z","slug":"CVE-2025-59699","body":"## Overview\n\nEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.\n\n## Affected\n\n- `nshield_5c_firmware < 13.6.12`\n- `nshield_5c_firmware >= 13.7, < 13.9.0`\n- `nshield_hsmi_firmware < 13.6.12`\n- `nshield_hsmi_firmware >= 13.7, < 13.9.0`\n- `nshield_connect_xc_base_firmware < 13.6.12`\n- `nshield_connect_xc_base_firmware >= 13.7, < 13.9.0`\n- `nshield_connect_xc_mid_firmware < 13.6.12`\n- `nshield_connect_xc_mid_firmware >= 13.7, < 13.9.0`\n- `nshield_connect_xc_high_firmware < 13.6.12`\n- `nshield_connect_xc_high_firmware >= 13.7, < 13.9.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nshield_5c_firmware 13.9.0`\n- `nshield_hsmi_firmware 13.9.0`\n- `nshield_connect_xc_base_firmware 13.9.0`\n- `nshield_connect_xc_mid_firmware 13.9.0`\n- `nshield_connect_xc_high_firmware 13.9.0`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}