GHSA-g9v7-h8x8-w5vwMediumCVSS 6.8
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a...
🔗 CVE IDs covered (1)
📋 Description
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB Bootloader.
🔗 References (5)
- https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj
- https://nvd.nist.gov/vuln/detail/CVE-2025-59699
- https://www.entrust.com/use-case/why-use-an-hsm
- https://github.com/advisories/GHSA-g9v7-h8x8-w5vw
- https://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025