Armatura One door control ships 2023 ActiveMQ RCE flaw
A three-year-old deserialization bug stayed embedded in physical access controllers, leaving every unpatched install open to unauthenticated code execution at OS privilege.
TL;DR
CISA's bulletin covers five critical vulnerabilities in Armatura One physical access control, affecting all releases below v4.7.2 and below v4.6.1_USA. The lead bug is CVSS 9.8 unauthenticated remote code execution through an embedded ActiveMQ OpenWire listener. The rest are credential failures: fixed encryption keys, a hardcoded database superuser password, and plaintext database and broker logging. Facilities in communications, energy, manufacturing, and transportation should upgrade through official Armatura support.
The CVE that matters in CISA's Armatura One advisory isn't new. CVE-2023-46604 surfaced in 2023 as a deserialization flaw in Apache ActiveMQ's OpenWire marshaller. It lets an unauthenticated network attacker trigger deserialization of an arbitrary object graph before authentication is checked. Armatura One embeds ActiveMQ and exposes the OpenWire listener on the network by default, so every install below v4.7.2 (or below v4.6.1_USA) inherits the bug unchanged. CVSS 3.1 scores it 9.8: network attack vector, low complexity, no privileges, no user interaction, critical impact. Successful exploitation is arbitrary code execution at the highest privilege on the host operating system.
The other four CVEs are less exotic but just as damaging on a system that stands between people and a secured facility. Stored database and broker credentials are protected with AES-128-CBC under a fixed key and initialization vector, identical across every installation. The database superuser ships with a vendor-defined password. Backup routines write the full database connection string, superuser password included, to a host log in plaintext, and the message broker logs client passwords during normal operation. Any of these hands an attacker with local OS access, or a copy of the install package, the keys to the physical access system.
Facilities teams should treat this as an upgrade, not a debate. Armatura publishes the fix at v4.7.2 for the worldwide line and v4.6.1_USA for the USA release line, with download guidance through official technical support. The advisory names communications, critical manufacturing, energy, and transportation as affected sectors, and the product is deployed worldwide.
CISA doesn't say whether the ActiveMQ flaw has been exploited in the wild against Armatura One, and it sets no deployment deadline. But a 2023-severity-9.8 RCE still sitting inside a physical access platform in 2026 is the kind of finding that should push a door controller to the top of the patch queue, ahead of the next routine maintenance window.
Published ·Deep Fathom