VYPR
advisoryPublished Oct 1, 2026· 1 source

Critical Vulnerabilities in Armatura One ICS Software Expose Industrial Control Systems to Severe Risks

CISA has issued a critical advisory detailing multiple severe vulnerabilities in Armatura One industrial control system software, potentially allowing attackers to execute arbitrary code and gain full system control.

CISA has released a critical advisory highlighting a series of severe vulnerabilities within Armatura LLC's Armatura One industrial control system (ICS) software, versions prior to 4.7.2 and 4.6.1 (USA). These flaws, collectively rated with CVSS scores reaching 9.8, pose a significant threat to critical infrastructure sectors including communications, critical manufacturing, energy, and transportation systems worldwide.

The most critical vulnerability, CVE-2023-46604, stems from an embedded Apache ActiveMQ component within Armatura One. This component, by default, exposes its OpenWire protocol listener. The vulnerability allows unauthenticated network attackers to exploit a deserialization flaw in the OpenWire marshaller before any authentication checks occur. Successful exploitation enables arbitrary code execution with the highest level of privilege on the host operating system, granting attackers deep access and control.

Beyond the remote code execution risk, the advisory also details issues related to insecure credential and key management. CVE-2026-94591 points to the use of hard-coded cryptographic keys and credentials for database and message-broker access. While these credentials are encrypted, the encryption key and initialization vector are fixed and embedded within the software itself, making them identical across all installations. An attacker who obtains the encrypted configuration file can readily decrypt it using the publicly known key, gaining unauthorized access to sensitive data and system controls.

Further compounding the security concerns, CVE-2026-94592 reveals that the database initialization routine assigns a fixed, vendor-defined password to the database superuser account. This means that on deployments where this default password has not been manually changed, an attacker with operating system access can easily authenticate as the database superuser, leading to complete database compromise.

Additional vulnerabilities, including CVE-2026-94593 and CVE-2026-94594, are also noted, contributing to the overall risk profile. The advisory emphasizes that successful exploitation of these combined vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest privilege, or seize control of the physical access-control system.

Armatura LLC has released updated versions to address these critical flaws. Armatura One users should upgrade to version 4.7.2, and users of the USA release line should upgrade to version 4.6.1_USA. The company recommends contacting official technical support for guidance on obtaining and applying these essential upgrades. The advisory also provides links to a CSAF (Cybersecurity Asset Management Framework) summary for more detailed technical information.

The widespread deployment of Armatura One across critical infrastructure sectors globally underscores the significant potential impact of these vulnerabilities. The ability for unauthenticated attackers to achieve arbitrary code execution and gain administrative control over these systems presents a severe threat to operational continuity and national security. Organizations utilizing Armatura One are urged to prioritize patching and review their security configurations immediately.

This advisory serves as a stark reminder of the persistent security challenges within the Industrial Internet of Things (IIoT) and Operational Technology (OT) environments. The reliance on embedded components and the potential for deeply embedded flaws necessitate continuous vigilance, robust patching strategies, and comprehensive security assessments for all ICS software.

Synthesized by Vypr AI