CVE-2025-59695: Critical severity Entrust nShield Connect XC vulnerability
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, and nShield HSMi (F04)to a version that resolves this vulnerability.Fixed in 13.6.12 - Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, and nShield HSMi (F04)to a version that resolves this vulnerability.Fixed in 13.9.0 - Compensating control
Mitigate F04 by preventing users with OS root access from being able to alter firmware on the Chassis Management Board without authentication (e.g., restrict/monitor root access and the ability to reach the chassis management board).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59695?
CVE-2025-59695 is considered a critical vulnerability due to the potential for unauthorized firmware alteration by users with OS root access.
How do I fix CVE-2025-59695?
To mitigate CVE-2025-59695, ensure that OS root access is strictly controlled and consider updating to a patched version of the software that addresses this vulnerability.
Which products are affected by CVE-2025-59695?
CVE-2025-59695 affects Entrust nShield Connect XC, nShield 5c, and nShield HSMi versions up to and including 13.6.11 and starting from 13.7.
What kind of access is required to exploit CVE-2025-59695?
Exploitation of CVE-2025-59695 requires OS root access to the affected systems.
What is the impact of CVE-2025-59695?
The impact of CVE-2025-59695 includes potential unauthorized firmware modifications, which could compromise the security and integrity of the affected systems.