Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.6.12"
}
]
},
{
"events": [
{
"introduced": "13.7"
},
{
"fixed": "13.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.6.12"
}
]
},
{
"events": [
{
"introduced": "13.7"
},
{
"fixed": "13.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.6.12"
}
]
},
{
"events": [
{
"introduced": "13.7"
},
{
"fixed": "13.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.6.12"
}
]
},
{
"events": [
{
"introduced": "13.7"
},
{
"fixed": "13.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "13.6.12"
}
]
},
{
"events": [
{
"introduced": "13.7"
},
{
"fixed": "13.9.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59699.json"