CVE-2025-59705: Medium severity Entrust nShield Connect XC vulnerability
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, and nShield HSMito a version that resolves this vulnerability.Fixed in 13.6.12 - Upgrade
Upgrade
Entrust nShield Connect XC, nShield 5c, and nShield HSMito a version that resolves this vulnerability.Fixed in 13.9.0 - Configuration
Apply the vendor mitigation for 'Unauthorized Reactivation of the USB interface' (F01) by ensuring the USB interface cannot be enabled via chassis probe insertion during system boot.
Entrust nShield Connect XC / nShield 5c / nShield HSMi USB interface reactivation via chassis probe insertion during system boot = Disable enabling USB interface through chassis probe insertion during system boot
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59705?
CVE-2025-59705 is considered a high-severity vulnerability due to potential privilege escalation.
How do I fix CVE-2025-59705?
To mitigate CVE-2025-59705, ensure that the USB interface is disabled during the system boot of affected Entrust products.
Who is affected by CVE-2025-59705?
CVE-2025-59705 affects users of Entrust nShield Connect XC, nShield 5c, and nShield HSMi versions up to 13.6.11 and 13.7.
What is the nature of CVE-2025-59705?
CVE-2025-59705 allows a physically proximate attacker to escalate privileges by enabling the USB interface through chassis probe insertion.
Is there a workaround for CVE-2025-59705?
A potential workaround for CVE-2025-59705 is restricting physical access to affected systems to prevent unauthorized manipulation.