Security Advisory

CVE-2025-59699

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-02 00:00:00
Last updated 2026-08-26 15:29:24
Assigner mitre
CVSS score 6.8
State PUBLISHED

Description

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.