Impact
Armatura One's message broker mistakenly records client connection credentials and associated passwords in clear text during normal operation. This flaw enables anyone who can read the logs—whether a legitimate user, an attacker who gains temporary farm or a person inspecting a backup—to recover authentication data, thereby compromising confidentiality and potentially allowing credential replay or unauthorized access.
Affected Systems
The vulnerability affects Armatura LLC's Armatura One product, including the US release line. Versions up to and including V4.7.1 on the standard line and V4.3.1_USA on the US line are impacted. The vendor has issued corrective releases: V4.7.2 for the standard line and V4.6.1_USA for the US line. All affected deployments should upgrade to these versions.
Risk and Exploitability
The CVSS score of 5.1 signals moderate severity, while the EPSS score is not available, indicating no current evidence of exploitation in the wild. The issue is not listed in the CISA KEV catalog. An attacker must obtain read access to the broker's log files or a backup that contains them; the vulnerability does not provide a direct remote code execution path, but once the credentials are exposed, they can be leveraged for credential stuffing or other attacks.
OpenCVE Enrichment