CVE-2025-59695
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
02/12/2025
Last modified:
04/12/2025
Description
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



