CVE-2025-54964

HIGH

BAE SOCET GXP < 4.6.0.2 - Remote Code Execution via GXP Job Service

Title source: llm
STIX 2.1

Description

An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is configured for local-only access, this may allow for privilege escalation in certain situations. If the Job Service is network accessible, this may allow remote command execution.

Scores

CVSS v3 8.4
EPSS 0.0028
EPSS Percentile 19.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
baesystems/socet_gxp < 4.6.0.2
Published Oct 23, 2025
Tracked Since Feb 18, 2026