Armatura LLC Armatura One
Summary
Multiple vulnerabilities have been identified in Armatura LLC's Armatura One product, specifically affecting versions prior to 4.7.2 and 4.6.1 for the USA version. Successful exploitation could grant attackers unauthorized database access, arbitrary code execution with elevated privileges, or control over the physical access-control system.
IFF Assessment
The identified vulnerabilities allow for significant unauthorized access and control, posing a direct threat to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: November 23, 2023. Known ransomware use: Known.
Defender Context
This CISA alert highlights critical vulnerabilities in industrial control systems used in vital sectors like energy and transportation. Defenders should prioritize patching or mitigating these vulnerabilities, especially given the potential for unauthorized access and code execution. The wide deployment across sectors and worldwide underscores the broad risk and the need for vigilance.