CVE-2025-59705

EUVD-2025-200262
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
6.8 MEDIUM
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
entrustnshield_5c_firmware
𝑥
< 13.6.12
entrustnshield_5c_firmware
13.7 ≤
𝑥
< 13.9.0
entrustnshield_hsmi_firmware
𝑥
< 13.6.12
entrustnshield_hsmi_firmware
13.7 ≤
𝑥
< 13.9.0
entrustnshield_connect_xc_base_firmware
𝑥
< 13.6.12
entrustnshield_connect_xc_base_firmware
13.7 ≤
𝑥
< 13.9.0
entrustnshield_connect_xc_mid_firmware
𝑥
< 13.6.12
entrustnshield_connect_xc_mid_firmware
13.7 ≤
𝑥
< 13.9.0
entrustnshield_connect_xc_high_firmware
𝑥
< 13.6.12
entrustnshield_connect_xc_high_firmware
13.7 ≤
𝑥
< 13.9.0
𝑥
= Vulnerable software versions