E
ntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL legacy bootloader.
References
| Link | Resource |
|---|---|
| https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj | Exploit Third Party Advisory |
| https://www.entrust.com/use-case/why-use-an-hsm | Product |
| https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
History
08 Dec 2025, 19:42
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Entrust nshield Connect Xc Mid Firmware
Entrust nshield Connect Xc Mid Entrust Entrust nshield Hsmi Firmware Entrust nshield 5c Firmware Entrust nshield 5c Entrust nshield Connect Xc Base Firmware Entrust nshield Connect Xc High Entrust nshield Connect Xc High Firmware Entrust nshield Connect Xc Base Entrust nshield Hsmi |
|
| CPE | cpe:2.3:h:entrust:nshield_5c:-:*:*:*:*:*:*:* cpe:2.3:o:entrust:nshield_connect_xc_base_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:entrust:nshield_connect_xc_high:-:*:*:*:*:*:*:* cpe:2.3:o:entrust:nshield_hsmi_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:entrust:nshield_connect_xc_mid_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:entrust:nshield_connect_xc_base:-:*:*:*:*:*:*:* cpe:2.3:h:entrust:nshield_connect_xc_mid:-:*:*:*:*:*:*:* cpe:2.3:o:entrust:nshield_connect_xc_high_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:entrust:nshield_hsmi:-:*:*:*:*:*:*:* cpe:2.3:o:entrust:nshield_5c_firmware:*:*:*:*:*:*:*:* |
|
| References | () https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj - Exploit, Third Party Advisory | |
| References | () https://www.entrust.com/use-case/why-use-an-hsm - Product |
03 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj - | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
| CWE | CWE-1270 |
02 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-02 15:15
Updated : 2025-12-08 19:42
NVD link : CVE-2025-59698
Mitre link : CVE-2025-59698
CVE.ORG link : CVE-2025-59698
JSON object : View
Products Affected
CWE
CWE-1270
Generation of Incorrect Security Tokens