Machine-generated analysis · WAYSCloud LLM
Armatura One versions prior to 4.7.2 expose an unauthenticated ActiveMQ OpenWire listener.
Context
Armatura LLC Armatura One embeds Apache ActiveMQ and provides an access-control system. The advisory states that the OpenWire listener is exposed by default and contains a deserialization flaw (CVE-2023-46604) that can allow unauthenticated attackers to execute arbitrary code with highest host privileges. Armatura has released version 4.7.2 (or 4.6.1 for the USA) that resolves the issue.
Operator considerations
Check: Verify the installed Armatura One version is earlier than 4.7.2 (or 4.6.1 for USA).
Isolate: Restrict network access to the ActiveMQ OpenWire port until the system is upgraded.
Patch: Upgrade to Armatura One 4.7.2 (or 4.6.1 for USA) as provided by the vendor.
Log: Monitor for unexpected connections to the OpenWire listener.
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.
The following versions of Armatura LLC Armatura One are affected:
Armatura One
Read the full advisory on CISA →