Critical Vulnerabilities Discovered in Armatura LLC Armatura One Platform
Multiple CVEs including deserialization flaw and hard-coded credentials affect worldwide deployments
Key Takeaways
- Five CVEs affect Armatura One and Armatura One (USA) platforms, with CVE-2023-46604 the most severe at CVSS 9.8.
- The embedded Apache ActiveMQ OpenWire deserialization flaw allows unauthenticated remote code execution with highest privilege.
- Hard-coded cryptographic keys and initialization vectors enable decryption of stored credentials across all installations.
- Fixed vendor-defined database superuser passwords facilitate unauthorized database access.
- Patches V4.7.2 and V4.6.1_USA are available; immediate upgrade is recommended.
Related Security News
International Law Enforcement Disrupts KillSec Ransomware Operation, Alleged Mastermind Identified as Teenager
Law enforcement agencies from multiple countries have collaborated to disrupt the KillSec ransomware operation. According to reports, the alleged mastermind is a 16-year-old individual. The operation is accused of targeting roughly 500 victims worldwide over the past two years. The disruption marks a significant action against a ransomware group that has been active in extorting organizations globally.