<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:netapp:e-Series_santricity_web_services_proxy:-:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3anetappe-series_santricity_web_services_proxy-/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 17:06:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3anetappe-series_santricity_web_services_proxy-/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Armatura One Access Control Systems</title><link>https://feed.craftedsignal.io/briefs/2026-10-armatura-one-vulnerabilities/</link><pubDate>Thu, 01 Oct 2026 17:06:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-armatura-one-vulnerabilities/</guid><description>Multiple high-severity vulnerabilities in Armatura One, including an Apache ActiveMQ deserialization flaw, expose critical physical access-control infrastructure to remote code execution and credential compromise.</description><content:encoded><![CDATA[<p>Armatura LLC's Armatura One access-control platform contains several critical vulnerabilities that expose systems to unauthorized access and full compromise. The most severe, CVE-2023-46604, arises from an embedded Apache ActiveMQ component that enables unauthenticated remote code execution (RCE) via the OpenWire protocol listener. Additional vulnerabilities, including CVE-2026-94591, CVE-2026-94592, and CVE-2026-94593, stem from insecure default configurations such as hard-coded cryptographic keys, hard-coded database superuser passwords, and the logging of sensitive database credentials in plain text. These issues collectively allow an attacker to bypass authentication, decrypt sensitive configuration data, and gain elevated privileges on the host server. The affected products include Armatura One versions prior to 4.7.2 and Armatura One (USA) versions prior to 4.6.1. These systems are used across energy, communications, and critical manufacturing sectors, making them a high-value target for disruption or physical security breach.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker identifies an internet-exposed Armatura One server with the Apache ActiveMQ OpenWire listener active.</li>
<li>The attacker sends a crafted malicious object through the OpenWire protocol to exploit the CVE-2023-46604 deserialization flaw.</li>
<li>The server deserializes the object, resulting in arbitrary code execution with the highest level of privilege.</li>
<li>The attacker accesses the host filesystem to locate installation configuration files containing encrypted credentials.</li>
<li>Utilizing the hard-coded AES-128-CBC key recovered from the application binary (CVE-2026-94591), the attacker decrypts the stored configuration data.</li>
<li>The attacker leverages the recovered database superuser password (CVE-2026-94592) or credentials exposed in plaintext logs (CVE-2026-94593) to gain direct database access.</li>
<li>The attacker modifies access-control lists or system settings to gain persistent control over the facility's physical security systems.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to achieve full host system compromise, including the execution of arbitrary code with administrative privileges. Impact includes unauthorized access to critical databases, loss of integrity in physical access control, and the potential for complete control over security systems in sensitive environments like critical manufacturing and energy sector facilities.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Armatura One to version 4.7.2 or later, or Armatura One (USA) to version 4.6.1_USA or later, as specified in the vendor remediation guidance.</li>
<li>Perform a security review of all Armatura One deployments to ensure default credentials have been rotated and sensitive log files are restricted from unauthorized access.</li>
<li>Restrict network access to the Apache ActiveMQ OpenWire port (default port 61616) to trusted management subnets to mitigate CVE-2023-46604 if patching is delayed.</li>
<li>Hunt for unauthorized access to Armatura One configuration files and log directories on host systems.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>critical-infrastructure</category><category>access-control</category><category>remote-code-execution</category><category>ics</category></item></channel></rss>