---
id: CVE-2025-59699
title: >-
  Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or
  13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate
  attacker to escalate privileges by booting from a USB device with a valid root
  fi…
summary: >-
  Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or
  13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate
  attacker to escalate privileges by booting from a USB device with a valid root
  fi…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-290
vendor: entrust
product: nshield_5c_firmware
affected:
  - nshield_5c_firmware < 13.6.12
  - 'nshield_5c_firmware >= 13.7, < 13.9.0'
  - nshield_hsmi_firmware < 13.6.12
  - 'nshield_hsmi_firmware >= 13.7, < 13.9.0'
  - nshield_connect_xc_base_firmware < 13.6.12
  - 'nshield_connect_xc_base_firmware >= 13.7, < 13.9.0'
  - nshield_connect_xc_mid_firmware < 13.6.12
  - 'nshield_connect_xc_mid_firmware >= 13.7, < 13.9.0'
  - nshield_connect_xc_high_firmware < 13.6.12
  - 'nshield_connect_xc_high_firmware >= 13.7, < 13.9.0'
patched:
  - nshield_5c_firmware 13.9.0
  - nshield_hsmi_firmware 13.9.0
  - nshield_connect_xc_base_firmware 13.9.0
  - nshield_connect_xc_mid_firmware 13.9.0
  - nshield_connect_xc_high_firmware 13.9.0
published: '2025-12-02'
updated: '2026-08-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59699'
references:
  - url: 'https://github.com/advisories/GHSA-g9v7-h8x8-w5vw'
    label: cve@mitre.org
  - url: >-
      https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj
    label: cve@mitre.org
  - url: >-
      https://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025
    label: cve@mitre.org
  - url: 'https://www.entrust.com/use-case/why-use-an-hsm'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00329
epssPercentile: 0.26282
ingestedAt: '2026-08-26T16:46:30.148Z'
---

## Overview

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.

## Affected

- `nshield_5c_firmware < 13.6.12`
- `nshield_5c_firmware >= 13.7, < 13.9.0`
- `nshield_hsmi_firmware < 13.6.12`
- `nshield_hsmi_firmware >= 13.7, < 13.9.0`
- `nshield_connect_xc_base_firmware < 13.6.12`
- `nshield_connect_xc_base_firmware >= 13.7, < 13.9.0`
- `nshield_connect_xc_mid_firmware < 13.6.12`
- `nshield_connect_xc_mid_firmware >= 13.7, < 13.9.0`
- `nshield_connect_xc_high_firmware < 13.6.12`
- `nshield_connect_xc_high_firmware >= 13.7, < 13.9.0`

## Remediation

Upgrade past the affected range:

- `nshield_5c_firmware 13.9.0`
- `nshield_hsmi_firmware 13.9.0`
- `nshield_connect_xc_base_firmware 13.9.0`
- `nshield_connect_xc_mid_firmware 13.9.0`
- `nshield_connect_xc_high_firmware 13.9.0`
