CVE-2025-59702: Entrust Nshield 5c Firmware
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components.
Affected products
- Entrust Nshield 5c Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7, before 13.9.0 (fixed in 13.9.0)
- Entrust Nshield Connect Xc Base Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7, before 13.9.0 (fixed in 13.9.0)
- Entrust Nshield Connect Xc High Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7, before 13.9.0 (fixed in 13.9.0)
- Entrust Nshield Connect Xc Mid Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7, before 13.9.0 (fixed in 13.9.0)
- Entrust Nshield Hsmi Firmware: before 13.6.12 (fixed in 13.6.12); from 13.7, before 13.9.0 (fixed in 13.9.0)
Published 2025-12-02. Last modified 2026-08-26.