CVE Vulnerabilities

CVE-2025-59705

Improper Privilege Management

Published: Dec 02, 2025 | Modified: Dec 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka Unauthorized Reactivation of the USB interface or F01.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Nshield_5c_firmware Entrust * 13.6.12 (excluding)
Nshield_5c_firmware Entrust 13.7 (including) 13.9.0 (excluding)

Potential Mitigations

References