An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local users to abort jobs or read information without the permissions of the job owner.
References
| Link | Resource |
|---|---|
| https://www.baesystems.com/en-us/product/geospatial-exploitation-products | Product |
| https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54970 | Vendor Advisory Mitigation |
Configurations
History
31 Oct 2025, 20:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Baesystems
Baesystems socet Gxp |
|
| CPE | cpe:2.3:a:baesystems:socet_gxp:*:*:*:*:*:*:*:* | |
| References | () https://www.baesystems.com/en-us/product/geospatial-exploitation-products - Product | |
| References | () https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54970 - Vendor Advisory, Mitigation |
28 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
27 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 17:15
Updated : 2025-10-31 20:29
NVD link : CVE-2025-54970
Mitre link : CVE-2025-54970
CVE.ORG link : CVE-2025-54970
JSON object : View
Products Affected
baesystems
- socet_gxp
CWE
CWE-284
Improper Access Control
