Baesystems
Baesystems Socet GXP: vulnerabilities and CVEs
Baesystems Socet GXP has 8 published vulnerabilities, 8 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months8
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54965 | Medium (6.1) | 0.20% | — | Oct 27, 2025 | An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize the job ID parameter before using it in the job status page. An attacker who is able to social… |
| CVE-2025-54970 | Medium (6.5) | 0.25% | — | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local users to abort jobs or read information… |
| CVE-2025-54969 | Medium (6.1) | 0.14% | — | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into clicking a malicious link or visiting a… |
| CVE-2025-54968 | High (8.8) | 0.41% | — | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jobs, or local users to submit jobs that… |
| CVE-2025-54967 | Medium (6.5) | 0.36% | — | Oct 27, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An attacker who is able to social engineer a SOCET GXP user into opening a malicious file can trigger a… |
| CVE-2025-54966 | Medium (4.3) | 0.24% | — | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive information in certain situations, including local file paths and SOCET GXP version… |
| CVE-2025-54964 | High (8.4) | 0.31% | — | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is configured for local-only access, this… |
| CVE-2025-54963 | Medium (6.5) | 0.69% | — | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a crafted job request that grants read access to files on the filesystem with the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.