VYPR
Vendor

Armatura LLC

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2026-94591higOct 1, 2026
    risk 0.55cvss 8.4epss —

    Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across…

  • CVE-2026-94592higOct 1, 2026
    risk 0.55cvss 8.4epss —

    Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this…

  • CVE-2026-94593higOct 1, 2026
    risk 0.51cvss 7.8epss —

    Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system…

  • CVE-2026-94594medOct 1, 2026
    risk 0.26cvss 4.0epss —

    Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.