VulnerabilityModified
CVE-2025-59704
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password.
MEDIUM 4.6EPSS 0.26%
Does this matter?
Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.
Description
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- entrust/nshield 5c firmware · entrust/nshield hsmi firmware · entrust/nshield connect xc base firmware · entrust/nshield connect xc mid firmware · entrust/nshield connect xc high firmware
- Source
- cve@mitre.org
References
- https://github.com/advisories/GHSA-3c73-5g33-8g22
- https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwjExploit, Third Party Advisory
- https://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025
- https://www.entrust.com/use-case/why-use-an-hsmProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.