Critical Vulnerabilities Discovered in Armatura One Access Control Systems
CISA has issued an advisory identifying five security vulnerabilities in Armatura One physical access control systems that could allow attackers to gain unauthorized database access and execute arbitrary code. One of the flaws exploits an unauthenticated Apache ActiveMQ deserialization issue, potentially enabling complete compromise of the access control system. The vulnerabilities pose a significant risk to organizations relying on Armatura One for physical security infrastructure.
The Armatura One system represents a critical piece of infrastructure for many organizations managing physical entry points and building security. The identification of these five distinct flaws indicates a layered vulnerability across multiple system components. The specific threat involving Apache ActiveMQ is particularly concerning because it functions without requiring authentication, creating an entry point that threat actors could potentially exploit without credentials.
Organizations deploying Armatura One now face urgent decision-making regarding patching timelines and interim security measures. CISA's recommendations focus on practical mitigation strategies while updates are being developed and deployed, including network isolation techniques and careful management of remote access permissions. The advisory emphasizes that while this particular product hasn't yet been targeted in observed attacks, the underlying ActiveMQ vulnerability has proven exploitable in other systems globally.
These vulnerabilities could significantly impact institutions relying on Armatura One for security operations, including corporations, government facilities, and critical infrastructure sites. Exploitation may enable unauthorized facility access, disruption of security monitoring, or compromise of associated database systems containing sensitive employee and visitor information. Organizations may face operational disruption while implementing patches, and the incident highlights broader supply-chain security challenges within critical infrastructure protection systems. Rapid communication and coordinated patching efforts across affected deployments may help minimize real-world exposure.