CVE-2025-54964
BaseFortify
Publication date: 2025-10-23
Last updated on: 2025-10-28
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| baesystems | socet_gxp | to 4.6.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-77 | The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in BAE SOCET GXP before version 4.6.0.2 allows an attacker who can interact with the GXP Job Service to inject arbitrary executable files. Depending on the configuration, this can lead to privilege escalation if the service is local-only, or remote command execution if the service is accessible over a network.
How can this vulnerability impact me? :
The impact of this vulnerability can be severe. If exploited, it may allow an attacker to execute arbitrary commands on the affected system, potentially gaining elevated privileges or full control remotely, depending on the Job Service configuration.