Search
Find a vulnerability
Search criteria
4 vulnerabilities found for Armatura One (USA) by Armatura LLC
CVE-2026-94591 (GCVE-0-2026-94591)
Vulnerability from cvelistv5 – Published: 2026-10-02 21:54 – Updated: 2026-10-03 15:52
VLAI
EPSS
VEX
Title
Armatura LLC Armatura One Use of Hard-coded Cryptographic Key
Summary
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:49 UTC
CWE
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Armatura LLC | Armatura One |
Affected:
0 , < 4.7.2
(custom)
Unaffected: 4.7.2 |
|
| Armatura LLC | Armatura One (USA) |
Affected:
0 , < 4.6.1
(custom)
Unaffected: 4.6.1_USA |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94591",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:49:28.338139Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:52:54.018Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Armatura One",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.7.2",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.7.2"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Armatura One (USA)",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.6.1_USA"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Andrew Capobianco of RewCon.co reported this vulnerability to CISA."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file."
}
],
"value": "Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-321",
"description": "CWE-321",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T21:54:42.665Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-01.json"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eArmatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\u003c/p\u003e\u003cp\u003eArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\u003c/p\u003e\u003cp\u003eArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.\u003c/p\u003e"
}
],
"value": "Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\n\n\n\nArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\n\n\n\nArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade."
}
],
"source": {
"advisory": "ICSA-26-274-01",
"discovery": "EXTERNAL"
},
"title": "Armatura LLC Armatura One Use of Hard-coded Cryptographic Key",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2026-94591",
"datePublished": "2026-10-02T21:54:42.665Z",
"dateReserved": "2026-09-21T21:13:53.727Z",
"dateUpdated": "2026-10-03T15:52:54.018Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94592 (GCVE-0-2026-94592)
Vulnerability from cvelistv5 – Published: 2026-10-02 21:52 – Updated: 2026-10-03 15:52
VLAI
EPSS
VEX
Title
Armatura LLC Armatura One Use of Hard-coded Credentials
Summary
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:49 UTC
CWE
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Armatura LLC | Armatura One |
Affected:
0 , < 4.7.2
(custom)
Unaffected: 4.7.2 |
|
| Armatura LLC | Armatura One (USA) |
Affected:
0 , < 4.6.1
(custom)
Unaffected: 4.6.1_USA |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94592",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:49:57.364171Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:52:54.168Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Armatura One",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.7.2",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.7.2"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Armatura One (USA)",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.6.1_USA"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Andrew Capobianco of RewCon.co reported this vulnerability to CISA."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Armatura One\u0027s database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed."
}
],
"value": "Armatura One\u0027s database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "CWE-798",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T21:52:54.438Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-01.json"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eArmatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\u003c/p\u003e\u003cp\u003eArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\u003c/p\u003e\u003cp\u003eArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.\u003c/p\u003e"
}
],
"value": "Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\n\n\n\nArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\n\n\n\nArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade."
}
],
"source": {
"advisory": "ICSA-26-274-01",
"discovery": "EXTERNAL"
},
"title": "Armatura LLC Armatura One Use of Hard-coded Credentials",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2026-94592",
"datePublished": "2026-10-02T21:52:54.438Z",
"dateReserved": "2026-09-21T21:13:54.460Z",
"dateUpdated": "2026-10-03T15:52:54.168Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94593 (GCVE-0-2026-94593)
Vulnerability from cvelistv5 – Published: 2026-10-02 21:51 – Updated: 2026-10-03 15:52
VLAI
EPSS
VEX
Title
Armatura LLC Armatura One Insertion of Sensitive Information into Log File
Summary
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:49 UTC
CWE
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Armatura LLC | Armatura One |
Affected:
0 , < 4.7.2
(custom)
Unaffected: 4.7.2 |
|
| Armatura LLC | Armatura One (USA) |
Affected:
0 , < 4.6.1
(custom)
Unaffected: 4.6.1_USA |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94593",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:49:48.212126Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:52:54.296Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Armatura One",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.7.2",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.7.2"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Armatura One (USA)",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.6.1_USA"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Andrew Capobianco of RewCon.co reported this vulnerability to CISA."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Armatura One\u0027s backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available."
}
],
"value": "Armatura One\u0027s backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T21:51:00.902Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-01.json"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eArmatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\u003c/p\u003e\u003cp\u003eArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\u003c/p\u003e\u003cp\u003eArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.\u003c/p\u003e"
}
],
"value": "Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\n\n\n\nArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\n\n\n\nArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade."
}
],
"source": {
"advisory": "ICSA-26-274-01",
"discovery": "EXTERNAL"
},
"title": "Armatura LLC Armatura One Insertion of Sensitive Information into Log File",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2026-94593",
"datePublished": "2026-10-02T21:51:00.902Z",
"dateReserved": "2026-09-21T21:13:55.149Z",
"dateUpdated": "2026-10-03T15:52:54.296Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94594 (GCVE-0-2026-94594)
Vulnerability from cvelistv5 – Published: 2026-10-02 21:48 – Updated: 2026-10-03 15:52
VLAI
EPSS
VEX
Title
Armatura LLC Armatura One Insertion of Sensitive Information into Log File
Summary
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-03 15:50 UTC
CWE
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Armatura LLC | Armatura One |
Affected:
0 , < 4.7.2
(custom)
Unaffected: 4.7.2 |
|
| Armatura LLC | Armatura One (USA) |
Affected:
0 , < 4.6.1
(custom)
Unaffected: 4.6.1_USA |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94594",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-03T15:50:14.687575Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T15:52:54.425Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Armatura One",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.7.2",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.7.2"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Armatura One (USA)",
"vendor": "Armatura LLC",
"versions": [
{
"lessThan": "4.6.1",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.6.1_USA"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Andrew Capobianco of RewCon.co reported this vulnerability to CISA."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Armatura One\u0027s message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential."
}
],
"value": "Armatura One\u0027s message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "NONE",
"baseScore": 4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T21:48:14.765Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01"
},
{
"url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-01.json"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eArmatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\u003c/p\u003e\u003cp\u003eArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\u003c/p\u003e\u003cp\u003eArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade.\u003c/p\u003e"
}
],
"value": "Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2.\n\n\n\nArmatura LLC has released Armatura One V4.6.1_USA, which resolves this issue. Users of the USA release line should upgrade from V4.3.1_USA or earlier to V4.6.1_USA.\n\n\n\nArmatura LLC recommends contacting official technical support for guidance on obtaining and applying the upgrade."
}
],
"source": {
"advisory": "ICSA-26-274-01",
"discovery": "EXTERNAL"
},
"title": "Armatura LLC Armatura One Insertion of Sensitive Information into Log File",
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2026-94594",
"datePublished": "2026-10-02T21:48:14.765Z",
"dateReserved": "2026-09-21T21:13:55.828Z",
"dateUpdated": "2026-10-03T15:52:54.425Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}