CVE-2025-59704
MEDIUMDescription
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is has no password.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| entrust | nshield_5c_firmware |
| entrust | nshield_5c_firmware |
| entrust | nshield_5c |
| entrust | nshield_hsmi_firmware |
| entrust | nshield_hsmi_firmware |
| entrust | nshield_hsmi |
| entrust | nshield_connect_xc_base_firmware |
| entrust | nshield_connect_xc_base_firmware |
| entrust | nshield_connect_xc_base |
| entrust | nshield_connect_xc_mid_firmware |
| entrust | nshield_connect_xc_mid_firmware |
| entrust | nshield_connect_xc_mid |
| entrust | nshield_connect_xc_high_firmware |
| entrust | nshield_connect_xc_high_firmware |
| entrust | nshield_connect_xc_high |
References
Frequently Asked Questions
What is CVE-2025-59704? +
How severe is CVE-2025-59704? +
What products are affected by CVE-2025-59704? +
How do I check if I'm vulnerable to CVE-2025-59704? +
Related Vulnerabilities
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated …
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication vulnerability was identified in OpenLearnX …
PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy …