CODERED VTA

Actively Exploited ActiveMQ Flaw and Hardcoded Keys Expose Armatura One Access Control Systems

High
Cabling behind data centre racks
Photo by D Coetzee on Flickr

CISA has published advisory ICSA-26-274-01 covering five vulnerabilities in Armatura LLC's Armatura One physical access-control platform. The affected builds are Armatura One below version 4.7.2 and the separate USA release line below version 4.6.1_USA, both of which carry the full set of issues: CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593 and CVE-2026-94594. The weakness classes involved are deserialization of untrusted data, use of a hard-coded cryptographic key, use of hard-coded credentials, and insertion of sensitive information into a log file. The highest-rated issue carries a CVSS v3.1 base score of 9.8 and a CVSS v4.0 score of 9.3. Successful exploitation can give an attacker unauthorised access to the product database, arbitrary code execution on the host with the highest level of privilege, or control of the physical access-control system itself. Armatura is headquartered in the United States, the product is deployed worldwide, and the advisory names the Communications, Critical Manufacturing, Energy and Transportation Systems sectors as users.

The most serious weakness is inherited rather than original. Armatura One embeds Apache ActiveMQ and exposes its OpenWire protocol listener on the network by default, and that embedded broker is affected by CVE-2023-46604, a flaw in the OpenWire marshaller. An unauthenticated attacker with network reach to the listener can trigger deserialization of an arbitrary object graph before any authentication check takes place, which leads to code execution at the highest privilege level on the underlying host operating system. The second documented issue, CVE-2026-94591, concerns how the product protects secrets at rest: database and message-broker credentials are written to an install configuration file and encrypted with AES-128-CBC, but the key and initialization vector are fixed values compiled into the software and identical on every installation. Anyone holding a copy of the installation package can extract that key and IV, and can then decrypt the stored credentials of any installation whose configuration file they separately obtain, which is why the issue is scored 8.4 under CVSS v3.1 with a local attack vector. The advisory classifies the remaining entries under hard-coded credentials and sensitive information written into log files; the published summary does not break out a step-by-step exploitation path for each of those.

The consequences described in ICSA-26-274-01 reach beyond data loss. CISA states that successful exploitation of these vulnerabilities could allow an attacker to gain unauthorised access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system itself, so a single compromised server can translate directly into control over doors and badge records rather than merely over stored information. CVE-2023-46604 is listed in the CISA Known Exploited Vulnerabilities catalog, which marks it as confirmed exploitation in the wild rather than a theoretical risk, and it is the issue CISA scores highest at CVSS v3.1 9.8 and CVSS v4.0 9.3 with the OpenWire listener exposed on the network by default. The hard-coded cryptographic key weakness widens the blast radius differently, because the key and initialization vector are the same in every copy of the installation package, so recovery of those fixed values once applies to the stored database and broker credentials of any installation worldwide. Armatura has released fixed builds as V4.7.2 and V4.6.1_USA, which leaves the exposure concentrated in deployments still running V4.7.1 or earlier and V4.3.1_USA or earlier. CISA records the product as deployed worldwide across the Communications, Critical Manufacturing, Energy and Transportation Systems sectors, so the affected population includes operators for whom door control is a safety function as much as a security one.

Attack Surface

Infrastructure, Database, Server OS, IoT

Tactics

Initial Access, Execution, Credential Access, Impact

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1059 – Command and Scripting Interpreter
  • T1552.001 – Unsecured Credentials: Credentials In Files
  • T1486 – Data Encrypted for Impact

SuperPRO's Threat Countermeasures Procedures

  1. Upgrade Armatura One to V4.7.2, which the vendor states resolves all five issues in ICSA-26-274-01; installations on V4.7.1 or earlier are affected. Armatura directs users to its official technical support to obtain and apply the upgrade package.
  2. For the USA release line, upgrade to V4.6.1_USA; deployments on V4.3.1_USA or earlier are affected by the same five CVEs and are not covered by the V4.7.2 build.
  3. Block untrusted network access to the embedded Apache ActiveMQ OpenWire protocol listener that Armatura One exposes by default, restricting it to the management VLAN or to explicitly allow-listed controller addresses until the upgrade is applied, since CVE-2023-46604 is exploitable pre-authentication over that listener.
  4. Rotate every database and message-broker credential stored in the Armatura One install configuration file after upgrading, because CVE-2026-94591 encrypted them with an AES-128-CBC key and IV that are identical in every copy of the installation package and are therefore permanently compromised.
  5. Hunt for CVE-2023-46604 exploitation on Armatura One hosts by alerting on the broker Java process spawning child interpreters such as cmd.exe, powershell.exe or /bin/sh, and on outbound retrieval of remote XML bean configuration files by that process, which is the standard pattern for this ActiveMQ flaw in ransomware intrusions.
  6. Review and restrict access to Armatura One application and installer log files for plaintext secrets, and purge historical logs, addressing the insertion-of-sensitive-information-into-log-file weakness recorded under CVE-2026-94594 in this advisory.
  7. Treat Armatura One servers as crown-jewel assets in access-control segmentation: audit badge records, door-unlock events and administrator accounts created on unpatched hosts for unauthorised changes, as code execution on the host grants control of the physical access-control system.

Source

Code Red Cyber / VTA – coderedcyber.ai