CVE-2025-59700: Medium severity Entrust nShield Connect XC vulnerability
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, and nShield HSMito a version that resolves this vulnerability.Fixed in 13.6.12 - Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, and nShield HSMito a version that resolves this vulnerability.Fixed in 13.9.0 - Compensating control
Limit physical access to the device/Recovery Partition to prevent a physically proximate attacker with root access from modifying the Recovery Partition (issue due to lack of integrity protection).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59700?
CVE-2025-59700 has a high severity due to the potential for physical attacks leading to unauthorized modification of critical system components.
How do I fix CVE-2025-59700?
To mitigate CVE-2025-59700, ensure to secure physical access to Entrust nShield devices and apply the latest security updates provided by the vendor.
Who is affected by CVE-2025-59700?
CVE-2025-59700 affects Entrust nShield Connect XC, nShield 5c, and nShield HSMi versions 13.6.11 and 13.7.
What type of attack does CVE-2025-59700 allow?
CVE-2025-59700 allows a physically proximate attacker with root access to modify the Recovery Partition due to lack of integrity protection.
What is the impact of CVE-2025-59700?
The impact of CVE-2025-59700 can lead to unauthorized access and manipulation of sensitive recovery mechanisms within the affected Entrust devices.