Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.06% | — | Ironmace IronshieldAI | 25/9/2026 | 30/9/2026 | IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root G4") instead of parsing and validating the PKCS signature data. As a result, a… | |
| Modificada | Media (4.6) | 0.26% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password. | |
| Modificada | Crítica (9.1) | 0.46% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker needs to remove the tamper label and… | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis probe insertion during system boot, aka "Unauthorized Reactivation of the USB… | |
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components. | |
| Modificada | Media (4.1) | 0.19% | — | Entrust Nshield Connect XC High FirmwareEntrust Nshield Connect XC MID FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Hsmi Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker (with elevated privileges) to read and modify the Appliance SSD contents (because they are unencrypted). | |
| Modificada | Baja (3.9) | 0.18% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of integrity protection). | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by booting from a USB device with a valid root filesystem. This occurs because of insecure default settings in the Legacy GRUB… | |
| Modificada | Media (6.8) | 0.33% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader. | |
| Modificada | Alta (7.2) | 0.31% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host OS. This is called F06. | |
| Modificada | Baja (3.2) | 0.24% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board. | |
| Modificada | Crítica (9.8) | 0.67% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04. | |
| Modificada | Media (6.8) | 0.32% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to persistently modify firmware and influence the (insecurely configured) appliance boot process. To exploit this, the… | |
| Modificada | Crítica (9.8) | 0.90% | — | Entrust Nshield 5C FirmwareEntrust Nshield Hsmi FirmwareEntrust Nshield Connect XC Base FirmwareEntrust Nshield Connect XC MID Firmware+1 | 2/12/2025 | 26/8/2026 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving… | |
| Modificada | Alta (7.5) | 2.7% | — | Unshield Project Unshield | 28/8/2017 | 17/6/2026 | Directory traversal vulnerability in unshield 1.0-1. | |
| Modificada | Media (6.8) | 0.35% | — | Thalesesecurity Nshield Connect Firmware | 18/8/2017 | 17/6/2026 | Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key [KNETI] and impersonate the nShield Connect device on a network, affect the integrity and… | |
| Modificada | Baja (2.6) | 0.92% | — | Ncipher Dse200 Document Sealing EngineNcipher NcoreNcipher NforceNcipher Securedb+4 | 9/3/2006 | 16/6/2026 | nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote… | |
| Modificada | Baja (2.1) | 0.34% | — | Ncipher Nshield | 23/11/2004 | 16/6/2026 | Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands. | |
| Modificada | Media (4.6) | 0.40% | — | Ncipher NforceNcipher Nshield | 4/10/2002 | 16/6/2026 | The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges. |