Impact
Armatura One’s backup and restore process logs the full database connection command, including the superuser password, in plain text on the host. If an adversary obtains OS access to the server, the exposed credentials provide direct access to the underlying database, potentially allowing full data exfiltration or modification. This vulnerability reflects the CWE-532 weakness of unprotected log data.
Affected Systems
Armatura LLC’s Armatura One application, including both the standard and USA releases. Versions earlier than V4.7.2 for the standard line and earlier than V4.6.1_USA for the USA line are affected.
Risk and Exploitability
The CVSS score of 8.5 indicates a high impact vulnerability. The EPSS score is not available, and the issue has not yet been listed in CISA’s KEV catalog. Attackers would need local or remote OS-level access to read the log file; there is no known publicly available remote exploitation vector. Once OS access is achieved, the disclosed credentials represent a critical credential compromise that can be leveraged to gain database control.
OpenCVE Enrichment