PT-2025-48707 · Entrust · Nshield Connect Xc+2

Published

2025-12-02

·

Updated

2026-01-06

·

CVE-2025-59704

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Entrust nShield Connect XC versions through 13.6.11 Entrust nShield 5c versions through 13.6.11 Entrust nShield HSMi versions through 13.6.11 Entrust nShield Connect XC version 13.7 Entrust nShield 5c version 13.7 Entrust nShield HSMi version 13.7
Description The Entrust nShield Connect XC, nShield 5c, and nShield HSMi devices lack a password to access the BIOS menu, potentially allowing an attacker to gain access.
Recommendations Entrust nShield Connect XC versions through 13.6.11 should be updated. Entrust nShield 5c versions through 13.6.11 should be updated. Entrust nShield HSMi versions through 13.6.11 should be updated. Entrust nShield Connect XC version 13.7 should be updated. Entrust nShield 5c version 13.7 should be updated. Entrust nShield HSMi version 13.7 should be updated.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-59704
GHSA-6Q4X-M86J-GFWJ

Affected Products

Nshield 5C
Nshield Connect Xc
Nshield Hsmi