Upgrade Armatura One to V4.7.2 (global) or V4.6.1_USA (USA line) at the earliest opportunity. Contact Armatura LLC official technical support for guidance on obtaining and applying upgrades. Refer to CISA advisory ICSA-26-274-01 for additional mitigation guidance. Restrict network access to the ActiveMQ OpenWire listener where possible.
Quick answers
What is CVE-2023-46604?
Upgrade Armatura One to V4.7.2 (global) or V4.6.1_USA (USA line) at the earliest opportunity. Contact Armatura LLC official technical support for guidance on obtaining and applying upgrades. Refer to CISA advisory ICSA-26-274-01 for additional mitigation guidance. Restrict network access to the ActiveMQ OpenWire listener where possible.
How severe is CVE-2023-46604?
critical, CVSS 9.8
Is CVE-2023-46604 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2023-46604 be mitigated?
Upgrade Armatura One to V4.7.2 (global) or V4.6.1_USA (USA line) at the earliest opportunity. Contact Armatura LLC official technical support for guidance on obtaining and applying upgrades. Refer to CISA advisory ICSA-26-274-01 for additional mitigation guidance. Restrict network access to the ActiveMQ OpenWire listener where possible.
CVSS
9.8
Vendor
Armatura LLC
Published
Oct 2, 2026 · 03:05
Patch
Unknown / not confirmed
Affected products
Armatura One, Armatura One (USA)
Mitigation
Upgrade Armatura One to V4.7.2 (global) or V4.6.1_USA (USA line) at the earliest opportunity. Contact Armatura LLC official technical support for guidance on obtaining and applying upgrades. Refer to CISA advisory ICSA-26-274-01 for additional mitigation guidance. Restrict network access to the ActiveMQ OpenWire listener where possible.
Armatura LLC's Armatura One and Armatura One (USA) platforms are affected by five vulnerabilities spanning critical and high severity. The most severe, CVE-2023-46604, is a deserialization flaw in embedded Apache ActiveMQ that allows unauthenticated remote code execution with highest privilege. Additional issues involve hard-coded cryptographic keys, fixed database passwords, and sensitive data leakage into logs. Versions prior to 4.7.2 (global) and 4.6.1_USA are affected. Patches have been released.