IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Armatura LLC Armatura One

CRITICAL
CVSS 9.8
Date 2026-10-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.

// Vulnerabilities (5)

CVE ID CVSS Score Severity Description
CVE-2026-94592 8.4 high
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
CVE-2026-94593 7.8 high
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
CVE-2023-46604 9.8 critical
Armatura One embeds Apache ActiveMQ, exposing its OpenWire protocol listener on the network by default. This embedded version is affected by CVE-2023-46604, a deserialization flaw in the OpenWire marshaller that allows an unauthenticated network attacker to trigger deserialization of an arbitrary object graph before authentication is checked. This can result in arbitrary code execution with the highest level of privilege on the host operating system.
CVE-2026-94594 4.0 medium
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
CVE-2026-94591 8.4 high
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.

// Remediations (6)

Mitigation: For more information see the associated CISA security advisory ICSA-26-274-01 JSON.
For more information see the associated CISA security advisory ICSA-26-274-01 JSON.
Patch: Armatura LLC recommends contacting official technical support for guidance on obtaining and applying
Armatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.
Patch: Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which reso
Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.
Patch: Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA,
Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.
Mitigation: Delta Electronics states that this issue was fixed by version 1.0.11 released in December 2023. Del
Delta Electronics states that this issue was fixed by version 1.0.11 released in December 2023. Delta recommends updating to version 1.0.11 or later.
Patch: Update to V2501 or later version and install the latest available version of Tableau Server as descr
Update to V2501 or later version and install the latest available version of Tableau Server as described in https://support.sw.siemens.com/knowledge-base/PL8822108

// References