CVE-2025-59700
⚪ Do wiadomości
Brak ochrony integralności w Entrust nShield umożliwia modyfikację partycji odzyskiwania przez atakującego.
CVSS
3.9
EPSS
0.2%
Exploit
poc
Vendor
entrust
Opis źródłowy (NVD)
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection).
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.9 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-12-02 15:15:55 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-26 16:16:23 UTC |
Referencje
- https://github.com/advisories/GHSA-qmq3-q8h7-g3v7 (cve@mitre.org)
- https://github.com/google/security-research/security/advisories/GHSA-6q4x-m86j-gfwj (cve@mitre.org) [Exploit, Third Party Advisory]
- https://www.entrust.com/knowledgebase/hardware/understanding-nshield-security-advisory-september-2025 (cve@mitre.org)
- https://www.entrust.com/use-case/why-use-an-hsm (cve@mitre.org) [Product]