The US Cybersecurity and Infrastructure Security Agency has published an advisory covering several vulnerabilities in Armatura One, a platform used to administer physical access-control systems. CISA says successful exploitation could expose database information, enable code execution or allow an attacker to take control of access-control functions.
Affected versions and security impact
The advisory covers Armatura One versions earlier than 4.7.2 and the US edition earlier than 4.6.1. The reported issues include embedded ActiveMQ vulnerability CVE-2023-46604 as well as four newly assigned CVEs affecting the platform. CISA lists a maximum CVSS v3 base score of 9.8.
The agency notes that CVE-2023-46604 appears in its Known Exploited Vulnerabilities catalog because it has been used against other products. CISA says it is not aware of public exploitation specifically targeting Armatura One. That distinction matters: operators should treat the exposure seriously without assuming that every installation has already been compromised.
What access-control operators should do
Armatura recommends upgrading to version 4.7.2, or 4.6.1_USA for the US edition. Owners should first inventory management servers, restrict administrative interfaces to trusted networks and preserve configuration backups before changing production systems.
Because the platform can influence doors and credentials, remediation should be coordinated with physical-security teams, not handled as an isolated IT patch. Administrators should also review service accounts, database access and logs for unexpected changes. SectechMedia’s access-control and identity coverage provides additional context for securing controller and credential-management environments.

Leave a Reply