Security/ security · access-control · cisa · vulnerabilities

Armatura One Access Control Systems Have Five Critical Bugs

A three-year-old Apache ActiveMQ flaw and four homegrown bugs let an unauthenticated attacker fully take over Armatura's door-control servers.

A three-year-old, already-weaponized bug in a bundled Apache component means some physical security systems can be taken over with zero credentials.

CISA's October 1 advisory covers Armatura One, access control software deployed worldwide across critical manufacturing, energy, transportation and communications sites. Versions before 4.7.2 (4.6.1_USA for the US release line) carry five flaws rated up to CVSS 9.8. The worst, CVE-2023-46604, sits in an embedded copy of Apache ActiveMQ whose network listener is exposed by default, letting an unauthenticated attacker trigger code execution with top-level privileges. The other four stack hardcoded encryption keys, a fixed database superuser password set at install, and two logging bugs that write plaintext database and broker credentials to disk during routine backups and normal operation. Armatura has patched all five; anyone on 4.7.1 or earlier needs to upgrade.

CVE-2023-46604 isn't obscure. It's the same ActiveMQ deserialization hole that ransomware operators started exploiting within days of its 2023 disclosure, hitting exposed servers across unrelated industries. Finding it still live and exposed by default in door-control hardware three years later says less about clever new attacks and more about how slowly physical security vendors patch the open-source components sitting inside their products. Pair that with hardcoded passwords and plaintext credential logging, and an intruder barely needs skill, just a target that hasn't updated.

Access control software is enterprise software that happens to be bolted to a door, and it inherits every bad patching habit that comes with that label.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →