PT-2025-48706 · Entrust · Entrust Nshield Connect Xc+2

Published

2025-12-02

·

Updated

2025-12-02

·

CVE-2025-59703

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Entrust nShield Connect XC versions through 13.6.11 Entrust nShield 5c versions through 13.6.11 Entrust nShield HSMi versions through 13.6.11 Entrust nShield Connect XC version 13.7 Entrust nShield 5c version 13.7 Entrust nShield HSMi version 13.7
Description A physically proximate attacker can access the internal components of the appliance without leaving tamper evidence. Exploitation requires removing the tamper label and all fixing screws from the device without causing damage, an action referred to as an F14 attack.
Recommendations For Entrust nShield Connect XC versions through 13.6.11, ensure physical security measures are in place to prevent unauthorized access to the device. For Entrust nShield 5c versions through 13.6.11, ensure physical security measures are in place to prevent unauthorized access to the device. For Entrust nShield HSMi versions through 13.6.11, ensure physical security measures are in place to prevent unauthorized access to the device. For Entrust nShield Connect XC version 13.7, ensure physical security measures are in place to prevent unauthorized access to the device. For Entrust nShield 5c version 13.7, ensure physical security measures are in place to prevent unauthorized access to the device. For Entrust nShield HSMi version 13.7, ensure physical security measures are in place to prevent unauthorized access to the device.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-59703
GHSA-6Q4X-M86J-GFWJ

Affected Products

Entrust Nshield 5C
Entrust Nshield Connect Xc
Entrust Nshield Hsmi