CVE-2025-59698: Medium severity Entrust nShield Connect XC vulnerability
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, nShield HSMito a version that resolves this vulnerability.Fixed in 13.6.12 - Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, nShield HSMito a version that resolves this vulnerability.Fixed in 13.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59698?
CVE-2025-59698 is considered to have a high severity due to the potential for physical access exploitation.
How do I fix CVE-2025-59698?
To mitigate CVE-2025-59698, ensure your systems are updated to the latest firmware version available from Entrust.
Who is affected by CVE-2025-59698?
CVE-2025-59698 affects Entrust nShield Connect XC, nShield 5c, and nShield HSMi devices up to versions 13.6.11 and 13.7.
What kind of attack does CVE-2025-59698 facilitate?
CVE-2025-59698 allows a physically proximate attacker to gain unauthorized access to the legacy bootloader.
What is the recommendation for my Entrust nShield device regarding CVE-2025-59698?
It is recommended to immediately check for available firmware updates to remediate CVE-2025-59698.