Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Baesystems

First CVE: Oct 23, 2025Active for: 1 yearTotal CVEs: 8

BAE Systems maintains a narrow portfolio centered on specialized geospatial and imagery-analysis software such as SOCET GXP, products deployed in defense and intelligence workflows where access control and data protection are mission-critical. The recurring vulnerability pattern reflects the web-service and file-handling architecture of these tools, centering on improper access control, cross-site scripting, CSRF, path traversal, and sensitive-information exposure—a profile typical of enterprise analysis platforms where authentication boundaries and input sanitization are complex. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
8.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Baesystems over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2025
9 months ago
Most Recent CVE
Oct 27, 2025
272 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-54964HIGH
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrary executables. If the Job Service is c
Oct 23, 20258.427NONO
CVE-2025-54968HIGH
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jo
Oct 27, 20258.825NONO
CVE-2025-54970MEDIUM
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, this may allow remote or local use
Oct 27, 20256.522NONO
CVE-2025-54963MEDIUM
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a crafted job request that grants read access
Oct 23, 20256.522NONO
CVE-2025-54965MEDIUM
An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize the job ID parameter before using it in the job status page
Oct 27, 20256.121NONO
CVE-2025-54969MEDIUM
An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social engineers a valid user into cl
Oct 27, 20256.121NONO
CVE-2025-54967MEDIUM
An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An attacker who is able to social engineer a SOCET GXP user into o
Oct 27, 20256.520NONO
CVE-2025-54966MEDIUM
An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive information in certain situations, including local
Oct 23, 20254.316NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
75%
25%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None4 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Baesystems.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Baesystems — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Baesystems's Products

View all 1 CNAs →

Top CWEs