โ† Back to Feed

Armatura LLC Armatura One

CVE-2023-46604CVE-2026-94591CVE-2026-94592CVE-2026-94593CVE-2026-94594

October 1, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL

Armatura One physical access control system has five vulnerabilities including a critical deserialization flaw (CVE-2023-46604) allowing unauthenticated remote code execution. Other flaws involve hard-coded credentials and keys. Fixed versions are available. ๐Ÿ“Œ **Analyst Note:** Physical access control systems are high-value targets; the combination of remote code execution and hard-coded credentials means attackers could gain persistent control over facility security, requiring immediate patching and credential rotation.

Key Takeaways

  • Armatura One physical access control system contains multiple vulnerabilities including a deserialization flaw (CVE-2023-46604) that allows unauthenticated remote code execution with highest privileges.
  • Additional flaws include hard-coded cryptographic keys, hard-coded credentials, and insertion of sensitive information into log files, enabling unauthorized database access and system control.
  • Armatura has released version 4.7.2 for the standard product and 4.6.1 for the USA version; users must upgrade immediately to prevent full system compromise.
โ˜• Buy a Coffee