CVE-2025-54964

8.4

BAE Systems · SOCET GXP

A vulnerability in BAE SOCET GXP allows attackers with access to the GXP Job Service to inject arbitrary executables, leading to privilege escalation or remote command execution.

Executive summary

A critical vulnerability in BAE SOCET GXP allows for arbitrary code execution, posing a severe risk of system compromise if the GXP Job Service is exposed to the network.

Vulnerability

The vulnerability exists within the GXP Job Service, where improper input handling allows an attacker to inject arbitrary executables. Depending on service configuration, this can result in local privilege escalation or remote command execution.

Business impact

The potential for remote command execution and privilege escalation represents a high severity risk to organizational infrastructure. With a CVSS score of 8.4, this flaw could allow unauthorized actors to gain full control over host systems, leading to data exfiltration, service disruption, and persistent unauthorized access.

Remediation

Immediate Action: Upgrade BAE SOCET GXP to version 4.6.0.2 or later to address the vulnerable Job Service component.

Proactive Monitoring: Audit network configurations to ensure the GXP Job Service is restricted to trusted internal networks and monitor server logs for unauthorized process execution attempts.

Compensating Controls: Deploy network segmentation or firewall rules to block external access to the GXP Job Service port, limiting the attack surface until the patch is deployed.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high CVSS score and the potential for remote command execution, this vulnerability should be prioritized for immediate remediation. IT administrators must verify the current version of SOCET GXP across all deployments and apply the update to version 4.6.0.2 without delay to prevent unauthorized system access.

Sources