Executive Summary
Facts Only
* Armatura One versions less than 4.7.2 and Armatura One (USA) versions less than 4.6.1 are affected.
* Vulnerability CVE-2023-46604 involves deserialization of untrusted data in the OpenWire marshaller, potentially allowing arbitrary code execution with the highest privilege on the host operating system.
* Vulnerability CVE-2026-94591 details that database and message-broker credentials are stored with fixed encryption keys and initialization vectors, making them recoverable by an attacker.
* Vulnerability CVE-2026-94592 indicates the database superuser account is assigned a fixed, vendor-defined password at creation time.
* Vulnerability CVE-2026-94593 involves recording the full database connection command, including the superuser password, in plain text within a host log file.
* Vulnerability CVE-2026-94594 involves message broker logs exposing client connection credentials and passwords in plain text.
* Remediation requires upgrading to Armatura One V4.7.2 or Armatura One V4.6.1USA.
Full Take
From the original · CISA Alerts
Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.Read the full story at cisa.gov
Sentinel — Human
The text presents highly structured, factual technical data typical of a security bulletin, strongly suggesting human authorship focused on reporting known vulnerabilities and remediation steps.
