Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Entrust Corporation

First CVE: Jul 27, 2001Active for: 25 yearsTotal CVEs: 18
16.0
VTI Score
Low

Entrust Corporation's vulnerability footprint centers on its nShield hardware security module (HSM) and key-management appliance portfolio, which occupies a critical role in cryptographic infrastructure and certificate lifecycle management across enterprise and financial institutions. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across firmware and base configurations through weakness classes including improper access control, privilege management flaws, authentication bypass via spoofing, and cleartext storage of sensitive data—exposures that directly threaten the confidentiality and integrity of key material and cryptographic operations. Defenders should treat HSM firmware updates as high-priority and verify access controls on management interfaces; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Entrust Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2001
24 years ago
Most Recent CVE
Dec 2, 2025
234 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-59695CRITICAL
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authe
Dec 2, 20259.829NONO
CVE-2025-59693CRITICAL
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to obtain debug access and
Dec 2, 20259.829NONO
CVE-2025-59703CRITICAL
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal components of the appliance, without
Dec 2, 20259.128NONO
CVE-2025-59702HIGH
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to falsify tamper events by access
Dec 2, 20257.224NONO
CVE-2025-59697HIGH
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloade
Dec 2, 20257.224NONO
CVE-2001-1024HIGH
login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath arg
Jul 27, 20017.524NONO
CVE-2025-59705MEDIUM
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface throug
Dec 2, 20256.823NONO
CVE-2025-59699MEDIUM
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by booting from a USB device with a
Dec 2, 20256.823NONO
CVE-2025-59694MEDIUM
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently modify fir
Dec 2, 20256.823NONO
CVE-2025-59698MEDIUM
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL legacy bootloader.
Dec 2, 20256.822NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
17%
44%
22%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (16.7%)
Unknown5 (27.8%)
Physical10 (55.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (72.2%)
High0 (0.0%)
Unknown5 (27.8%)
User Interaction
None13 (72.2%)
Unknown5 (27.8%)
Required0 (0.0%)
Privileges Required
Low2 (11.1%)
High3 (16.7%)
None8 (44.4%)
Unknown5 (27.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Entrust Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Entrust Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Entrust Corporation's Products

View all 1 CNAs →

Top CWEs