CVE-2025-54968

8.8

BAE Systems · SOCET GXP

The SOCET GXP Job Service lacks proper authentication, allowing unauthorized users to submit jobs that may execute with the privileges of other users.

Executive summary

A critical authentication bypass vulnerability in BAE SOCET GXP allows unauthorized job submission and potential privilege escalation.

Vulnerability

The SOCET GXP Job Service fails to perform necessary authentication checks. This allows authenticated (low-privilege) users to submit jobs that execute with elevated permissions, potentially impacting system integrity and confidentiality.

Business impact

Successful exploitation of this vulnerability poses a significant risk to the integrity and availability of geospatial exploitation workflows. With a CVSS score of 8.8, this high-severity flaw could allow an attacker to execute arbitrary jobs within the system, potentially leading to unauthorized data manipulation or service disruption. Organizations relying on this software for critical operations face potential operational downtime and data compromise if the system is not promptly secured.

Remediation

Immediate Action: Update BAE SOCET GXP to version 4.6.0.2 or later to resolve the authentication flaw in the Job Service.

Proactive Monitoring: Audit job submission logs for unusual patterns or requests originating from unexpected user accounts.

Compensating Controls: Restrict network access to the SOCET GXP Job Service to trusted internal subnets only, effectively minimizing the attack surface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability, combined with its potential for privilege escalation, necessitates immediate attention. Administrators must prioritize the installation of the vendor-supplied patch to version 4.6.0.2. Failure to remediate this issue leaves the environment susceptible to unauthorized job execution and potential system-wide impact.

Sources