6.8
CVE-2025-59705
- EPSS 0.02%
- Veröffentlicht 02.12.2025 00:00:00
- Zuletzt bearbeitet 08.12.2025 19:39:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB interface" or F01.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Entrust ≫ Nshield 5c Firmware Version < 13.6.12
Entrust ≫ Nshield 5c Firmware Version >= 13.7 < 13.9.0
Entrust ≫ Nshield Hsmi Firmware Version < 13.6.12
Entrust ≫ Nshield Hsmi Firmware Version >= 13.7 < 13.9.0
Entrust ≫ Nshield Connect Xc Base Firmware Version < 13.6.12
Entrust ≫ Nshield Connect Xc Base Firmware Version >= 13.7 < 13.9.0
Entrust ≫ Nshield Connect Xc Mid Firmware Version < 13.6.12
Entrust ≫ Nshield Connect Xc Mid Firmware Version >= 13.7 < 13.9.0
Entrust ≫ Nshield Connect Xc High Firmware Version < 13.6.12
Entrust ≫ Nshield Connect Xc High Firmware Version >= 13.7 < 13.9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.052 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.