{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aapacheactivemq_legacy_openwire_module/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:activemq_legacy_openwire_module:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:a:netapp:e-series_santricity_unified_manager:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:e-series_santricity_web_services_proxy:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:santricity_storage_plugin:-:*:*:*:*:vcenter:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2023-46604"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Armatura One (\u003c4.7.2)","Armatura One (USA) (\u003c4.6.1)"],"_cs_severities":["critical"],"_cs_tags":["critical-infrastructure","access-control","remote-code-execution","ics"],"_cs_type":"advisory","_cs_vendors":["Armatura LLC"],"content_html":"\u003cp\u003eArmatura LLC's Armatura One access-control platform contains several critical vulnerabilities that expose systems to unauthorized access and full compromise. The most severe, CVE-2023-46604, arises from an embedded Apache ActiveMQ component that enables unauthenticated remote code execution (RCE) via the OpenWire protocol listener. Additional vulnerabilities, including CVE-2026-94591, CVE-2026-94592, and CVE-2026-94593, stem from insecure default configurations such as hard-coded cryptographic keys, hard-coded database superuser passwords, and the logging of sensitive database credentials in plain text. These issues collectively allow an attacker to bypass authentication, decrypt sensitive configuration data, and gain elevated privileges on the host server. The affected products include Armatura One versions prior to 4.7.2 and Armatura One (USA) versions prior to 4.6.1. These systems are used across energy, communications, and critical manufacturing sectors, making them a high-value target for disruption or physical security breach.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an internet-exposed Armatura One server with the Apache ActiveMQ OpenWire listener active.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted malicious object through the OpenWire protocol to exploit the CVE-2023-46604 deserialization flaw.\u003c/li\u003e\n\u003cli\u003eThe server deserializes the object, resulting in arbitrary code execution with the highest level of privilege.\u003c/li\u003e\n\u003cli\u003eThe attacker accesses the host filesystem to locate installation configuration files containing encrypted credentials.\u003c/li\u003e\n\u003cli\u003eUtilizing the hard-coded AES-128-CBC key recovered from the application binary (CVE-2026-94591), the attacker decrypts the stored configuration data.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the recovered database superuser password (CVE-2026-94592) or credentials exposed in plaintext logs (CVE-2026-94593) to gain direct database access.\u003c/li\u003e\n\u003cli\u003eThe attacker modifies access-control lists or system settings to gain persistent control over the facility's physical security systems.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to achieve full host system compromise, including the execution of arbitrary code with administrative privileges. Impact includes unauthorized access to critical databases, loss of integrity in physical access control, and the potential for complete control over security systems in sensitive environments like critical manufacturing and energy sector facilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Armatura One to version 4.7.2 or later, or Armatura One (USA) to version 4.6.1_USA or later, as specified in the vendor remediation guidance.\u003c/li\u003e\n\u003cli\u003ePerform a security review of all Armatura One deployments to ensure default credentials have been rotated and sensitive log files are restricted from unauthorized access.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Apache ActiveMQ OpenWire port (default port 61616) to trusted management subnets to mitigate CVE-2023-46604 if patching is delayed.\u003c/li\u003e\n\u003cli\u003eHunt for unauthorized access to Armatura One configuration files and log directories on host systems.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T17:06:06Z","date_published":"2026-10-01T17:06:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-armatura-one-vulnerabilities/","summary":"Multiple high-severity vulnerabilities in Armatura One, including an Apache ActiveMQ deserialization flaw, expose critical physical access-control infrastructure to remote code execution and credential compromise.","title":"Critical Vulnerabilities in Armatura One Access Control Systems","url":"https://feed.craftedsignal.io/briefs/2026-10-armatura-one-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:apache:activemq_legacy_openwire_module:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}