An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local users to abort jobs or read information without the permissions of the job owner.
References
| Link | Resource |
|---|---|
| https://www.baesystems.com/en-us/product/geospatial-exploitation-products | Product |
| https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54970 | Mitigation Vendor Advisory |
Configurations
History
17 Jun 2026, 09:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54970 - Mitigation, Vendor Advisory |
31 Oct 2025, 20:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Baesystems socet Gxp
Baesystems |
|
| CPE | cpe:2.3:a:baesystems:socet_gxp:*:*:*:*:*:*:*:* | |
| References | () https://www.baesystems.com/en-us/product/geospatial-exploitation-products - Product | |
| References | () https://www.geospatialexploitationproducts.com/content/socet-gxp/vulnerabilities-disclosure/#cve-2025-54970 - Vendor Advisory, Mitigation |
28 Oct 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
27 Oct 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-27 17:15
Updated : 2026-06-17 09:41
NVD link : CVE-2025-54970
Mitre link : CVE-2025-54970
CVE.ORG link : CVE-2025-54970
JSON object : View
Products Affected
baesystems
- socet_gxp
CWE
CWE-284
Improper Access Control
