CVE-2025-59696CWE-1263

CVE-2025-59696

Low · published December 2, 2025

CVSS v3.1
3.2
EPSS
0%
Percentile
14.9
In the wild
Unconfirmed
What it is

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board.

The record
Technical detail
CVSS v3.1
3.2 · LOW
Vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00239 · 14.9th percentile
Weakness
CWE-1263 · Improper Physical Access Control
Published
2025-12-02T20:15Z
Affected products (10)
ProductVersionsFixed in
entrust/nshield_5c_firmware< 13.6.1213.6.12
entrust/nshield_5c_firmware≥ 13.7, < 13.9.013.9.0
entrust/nshield_hsmi_firmware< 13.6.1213.6.12
entrust/nshield_hsmi_firmware≥ 13.7, < 13.9.013.9.0
entrust/nshield_connect_xc_base_firmware< 13.6.1213.6.12
entrust/nshield_connect_xc_base_firmware≥ 13.7, < 13.9.013.9.0
entrust/nshield_connect_xc_mid_firmware< 13.6.1213.6.12
entrust/nshield_connect_xc_mid_firmware≥ 13.7, < 13.9.013.9.0
entrust/nshield_connect_xc_high_firmware< 13.6.1213.6.12
entrust/nshield_connect_xc_high_firmware≥ 13.7, < 13.9.013.9.0
References (4)
EPSS history
Timeline
  • 02 DEC 00:00Z
    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to modify or erase tamper events via…
    cvelistv5