Entrust Corporation's vulnerability footprint centers on its nShield hardware security module (HSM) and key-management appliance portfolio, which occupies a critical role in cryptographic infrastructure and certificate lifecycle management across enterprise and financial institutions. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across firmware and base configurations through weakness classes including improper access control, privilege management flaws, authentication bypass via spoofing, and cleartext storage of sensitive data—exposures that directly threaten the confidentiality and integrity of key material and cryptographic operations. Defenders should treat HSM firmware updates as high-priority and verify access controls on management interfaces; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Entrust Corporation over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59695CRITICAL Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Authe | Dec 2, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-59693CRITICAL The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to obtain debug access and | Dec 2, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-59703CRITICAL Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal components of the appliance, without | Dec 2, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-59702HIGH Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to falsify tamper events by access | Dec 2, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-59697HIGH Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloade | Dec 2, 2025 | 7.2 | 24 | NO | NO |
CVE-2001-1024HIGH login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath arg | Jul 27, 2001 | 7.5 | 24 | NO | NO |
CVE-2025-59705MEDIUM Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface throug | Dec 2, 2025 | 6.8 | 23 | NO | NO |
CVE-2025-59699MEDIUM Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by booting from a USB device with a | Dec 2, 2025 | 6.8 | 23 | NO | NO |
CVE-2025-59694MEDIUM The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently modify fir | Dec 2, 2025 | 6.8 | 23 | NO | NO |
CVE-2025-59698MEDIUM Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL legacy bootloader. | Dec 2, 2025 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Entrust Corporation.
Media articles that mention a CVE ID that affects a product developed by Entrust Corporation — matched by CVE ID, not by vendor name.