Armatura LLC Armatura One
What happened
View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: < 4.7.2, Armatura LLC Armatura One (USA): < 4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/ < 4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. This embedded version is affected by CVE-2023-46604 (the public catalogue number for a specific software flaw), a deserialization flaw (a weakness in how software reads incoming data) in the OpenWire marshaller that allows an unauthenticated network attacker to trigger deserialization of an arbitrary object graph before authentication is checked. This can result in arbitrary code execution with the highest level of privilege on the host operating system.
Sources & evidence
- CISA Advisories Primary / official
Armatura LLC Armatura One ↗
https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01