Skip to main content

Vendor archive

entrust CVEs

Beta · best-effort

18 CVEs tagged to vendor entrust3 Critical, 4 High, 8 Medium, 3 Low, 0 Unrated.

CVE-2025-59704

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is has no password.

CVSS 4.6 · Medium

CVE-2025-59703

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal components of the appliance, withou…

CVSS 9.1 · Critical

CVE-2025-59705

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface throu…

CVSS 6.8 · Medium

CVE-2025-59702

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to falsify tamper events by acces…

CVSS 7.2 · High

CVE-2025-59701

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker (with elevated privileges) to read and modify the Applianc…

CVSS 4.1 · Medium

CVE-2025-59700

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with root access to modify the Recovery Partition (because…

CVSS 3.9 · Low

CVE-2025-59699

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by booting from a USB device with a…

CVSS 6.8 · Medium

CVE-2025-59698

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL legacy bootloader.

CVSS 6.8 · Medium

CVE-2025-59697

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootload…

CVSS 7.2 · High

CVE-2025-59696

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to modify or erase tamper events via the Chassis managemen…

CVSS 3.2 · Low

CVE-2025-59695

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to alter firmware on the Chassis Management Board (without Auth…

CVSS 9.8 · Critical

CVE-2025-59694

Published Dec 2, 2025

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to persistently modify fi…

CVSS 6.8 · Medium

CVE-2025-59693

Published Dec 2, 2025

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to obtain debug access an…

CVSS 9.8 · Critical

CVE-2007-4594

Published Aug 29, 2007

Entrust Entelligence Security Provider (ESP) 8 does not properly validate certificates in certain circumstances involving (1) a chain that omits the root Certification Authority (…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0712

Published Feb 3, 2004

Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform o…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0853

Published Dec 6, 2001

Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) Abo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1024

Published Jul 27, 2001

login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1