CVE-2025-54964 Details
Description
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is configured for local-only access, this may allow for privilege escalation in certain situations. If the Job Service is network accessible, this may allow remote command execution.
A command injection vulnerability has been identified in BAE SOCET GXP versions prior to 4.6.0.2. The issue arises in the GXP Job Service, which by default allows connections from all IP addresses. If the Job Service is not reconfigured during installation and is permitted through the local Windows Firewall (or if the firewall is disabled), a remote attacker can execute arbitrary commands with the privileges of the SOCET GXP Job Service. In Basic mode, the Job Service runs only when SOCET GXP is active, using the permissions of the user who launched the application.
Users are advised to update to SOCET GXP version 4.6.0.2 or later, which disables network access for the GXP Job Service by default. For those unable to update immediately, network access can be restricted by removing allowed IPs from the Job Service configuration window or by blocking access to the Job Service ports in the Windows Firewall. Assistance with these changes is available through BAE's Customer Technical Support.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| baesystems socet gxp | < 4.6.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 28, 2025 | Initial Analysis | [email protected] |
| Oct 24, 2025 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | New CVE Received | [email protected] |