Back to overview

CVE-2025-59693

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving evidence, and accessing the JTAG connector. This is called F02.

Metadata

CVE ID
CVE-2025-59693
State
PUBLISHED
Assigner
mitre
Reserved
2025-09-18 00:00 UTC
Published
2025-12-02 00:00 UTC
Last updated
2025-12-03 14:44 UTC
Primary CWE
CWE-269
CWE-269 Improper Privilege Management
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-269 adp CWE-269 Improper Privilege Management
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview