CVE-2025-59694

Source
https://cve.org/CVERecord?id=CVE-2025-59694
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59694.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-59694
Aliases
Related
  • GHSA-6q4x-m86j-gfwj
Published
2025-12-02T15:15:54.883Z
Modified
2026-03-14T12:44:12.316836Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the attacker must modify the firmware via JTAG or perform an upgrade to the chassis management board firmware. This is called F03.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "13.6.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "13.7.3"
            },
            {
                "fixed": "13.9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "13.6.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "13.7.3"
            },
            {
                "fixed": "13.9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "13.6.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "13.7.3"
            },
            {
                "fixed": "13.9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "13.6.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "13.7.3"
            },
            {
                "fixed": "13.9.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "13.6.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "13.7.3"
            },
            {
                "fixed": "13.9.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59694.json"