Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-59704

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
02/12/2025
Última modificación:
26/08/2026

Descripción

*** Pendiente de traducción *** Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:entrust:nshield_5c_firmware:*:*:*:*:*:*:*:* 13.6.12 (excluyendo)
cpe:2.3:o:entrust:nshield_5c_firmware:*:*:*:*:*:*:*:* 13.7 (incluyendo) 13.9.0 (excluyendo)
cpe:2.3:h:entrust:nshield_5c:-:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_hsmi_firmware:*:*:*:*:*:*:*:* 13.6.12 (excluyendo)
cpe:2.3:o:entrust:nshield_hsmi_firmware:*:*:*:*:*:*:*:* 13.7 (incluyendo) 13.9.0 (excluyendo)
cpe:2.3:h:entrust:nshield_hsmi:-:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_connect_xc_base_firmware:*:*:*:*:*:*:*:* 13.6.12 (excluyendo)
cpe:2.3:o:entrust:nshield_connect_xc_base_firmware:*:*:*:*:*:*:*:* 13.7 (incluyendo) 13.9.0 (excluyendo)
cpe:2.3:h:entrust:nshield_connect_xc_base:-:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_connect_xc_mid_firmware:*:*:*:*:*:*:*:* 13.6.12 (excluyendo)
cpe:2.3:o:entrust:nshield_connect_xc_mid_firmware:*:*:*:*:*:*:*:* 13.7 (incluyendo) 13.9.0 (excluyendo)
cpe:2.3:h:entrust:nshield_connect_xc_mid:-:*:*:*:*:*:*:*
cpe:2.3:o:entrust:nshield_connect_xc_high_firmware:*:*:*:*:*:*:*:* 13.6.12 (excluyendo)
cpe:2.3:o:entrust:nshield_connect_xc_high_firmware:*:*:*:*:*:*:*:* 13.7 (incluyendo) 13.9.0 (excluyendo)
cpe:2.3:h:entrust:nshield_connect_xc_high:-:*:*:*:*:*:*:*