Impact
Armatura One applies AES-128-CBC to encrypt database and message-broker credentials when protection is enabled. The cipher key and IV are hard-coded constants that are identical in every build. Because the key is embedded in the executable, an attacker who obtains the installation package can extract it and then, upon gaining the configuration file from a specific deployment, decrypt the credentials. This leads to a confidentiality breach of stored credentials, exposing user identities and system access.
Affected Systems
The vulnerability affects Armatura LLC's Armatura One product. Systems running versions up to and including V4.7.1 of the standard release line are impacted, as are systems using the USA release line up to V4.3.1_USA. The known CNA fixes introduce new builds: V4.7.2 for the standard line and V4.6.1_USA for the USA line.
Risk and Exploitability
With a CVSS score of 8.6, the flaw is considered high severity. No EPSS score is publicly available, and the vulnerability is not yet listed in CISA's KEV catalogue. Exploitation would require an attacker to first acquire the Armatura One installer and later obtain a copy of the encrypted configuration file from a target installation. While both conditions are non-trivial, the presence of a fixed key makes decryption straightforward once access is gained, giving the attacker immediate, unauthorized access to the application’s database and message-broker credentials.
OpenCVE Enrichment