PT-2025-43555 · Bae Systems · Bae Socet Gxp
Published
2025-10-23
·
Updated
2025-10-24
·
CVE-2025-54964
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BAE SOCET GXP versions prior to 4.6.0.2
Description
An attacker who can interact with the GXP Job Service may be able to inject arbitrary executables. If the Job Service is configured for local access, this could lead to privilege escalation. If the Job Service is accessible over a network, this could lead to remote command execution. The
GXP Job Service is the component at risk.Recommendations
Update BAE SOCET GXP to version 4.6.0.2 or later.
Fix
LPE
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bae Socet Gxp