Security Advisory

CVE-2025-59694

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-02 00:00:00
Last updated 2026-08-26 15:19:27
Assigner mitre
CVSS score 6.8
State PUBLISHED

Description

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the attacker must modify the firmware via JTAG or perform an upgrade to the chassis management board firmware. This is called F03.