An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is configured for local-only access, this may allow for privilege escalation in certain situations. If the Job Service is network accessible, this may allow remote command execution.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Thu, 23 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is configured for local-only access, this may allow for privilege escalation in certain situations. If the Job Service is network accessible, this may allow remote command execution. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-23T20:40:09.880Z
Reserved: 2025-08-04T00:00:00.000Z
Link: CVE-2025-54964
Updated: 2025-10-23T20:40:03.272Z
Status : Received
Published: 2025-10-23T20:15:39.853
Modified: 2025-10-23T21:15:44.533
Link: CVE-2025-54964
No data.
OpenCVE Enrichment
No data.