9.1

CVE-2025-59703

Exploit
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker needs to remove the tamper label and all fixing screws from the device without damaging it. This is called an F14 attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Entrust ≫ Nshield 5c Firmware Version < 13.6.12
   Entrust ≫ Nshield 5c Version -
Entrust ≫ Nshield 5c Firmware Version >= 13.7 < 13.9.0
   Entrust ≫ Nshield 5c Version -
Entrust ≫ Nshield Hsmi Firmware Version < 13.6.12
   Entrust ≫ Nshield Hsmi Version -
Entrust ≫ Nshield Hsmi Firmware Version >= 13.7 < 13.9.0
   Entrust ≫ Nshield Hsmi Version -
Entrust ≫ Nshield Connect Xc Base Firmware Version < 13.6.12
   Entrust ≫ Nshield Connect Xc Base Version -
Entrust ≫ Nshield Connect Xc Base Firmware Version >= 13.7 < 13.9.0
   Entrust ≫ Nshield Connect Xc Base Version -
Entrust ≫ Nshield Connect Xc Mid Firmware Version < 13.6.12
   Entrust ≫ Nshield Connect Xc Mid Version -
Entrust ≫ Nshield Connect Xc Mid Firmware Version >= 13.7 < 13.9.0
   Entrust ≫ Nshield Connect Xc Mid Version -
Entrust ≫ Nshield Connect Xc High Firmware Version < 13.6.12
   Entrust ≫ Nshield Connect Xc High Version -
Entrust ≫ Nshield Connect Xc High Firmware Version >= 13.7 < 13.9.0
   Entrust ≫ Nshield Connect Xc High Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.314
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://www.entrust.com/use-case/why-use-an-hsm
Product
https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj
Third Party Advisory
Exploit
https://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025
https://github.com/advisories/GHSA-h78c-68qv-3qg9