CVE-2025-59699Medium· 6.8▾ SunlitEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root fi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 26.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.
nshield_5c_firmware < 13.6.12nshield_5c_firmware >= 13.7, < 13.9.0nshield_hsmi_firmware < 13.6.12nshield_hsmi_firmware >= 13.7, < 13.9.0nshield_connect_xc_base_firmware < 13.6.12nshield_connect_xc_base_firmware >= 13.7, < 13.9.0nshield_connect_xc_mid_firmware < 13.6.12nshield_connect_xc_mid_firmware >= 13.7, < 13.9.0nshield_connect_xc_high_firmware < 13.6.12nshield_connect_xc_high_firmware >= 13.7, < 13.9.0Upgrade past the affected range:
nshield_5c_firmware 13.9.0nshield_hsmi_firmware 13.9.0nshield_connect_xc_base_firmware 13.9.0nshield_connect_xc_mid_firmware 13.9.0nshield_connect_xc_high_firmware 13.9.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59704Medium· 4.6Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password.
CVE-2025-59703Critical· 9.1Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamp…
CVE-2025-59705Medium· 6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis pro…
CVE-2025-59702High· 7.2Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal …
CVE-2025-59700Low· 3.9Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of …
CVE-2025-59698Medium· 6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader.