AI analysis
Armatura One's backup and restore routine writes the full database connection command, including the database superuser password, in plain text to a log file on the host. The disclosure occurs when backup or restore runs and records that command (CWE-532). An attacker who already has local access to the server operating system with low privileges can read the log and reuse the credentials to access the database, with high impact to confidentiality, integrity, and availability of the vulnerable system. Armatura One from Armatura LLC is affected; the advisory data does not name specific version ranges. No public proof of concept is known, and the issue is not listed in CISA KEV.
What to do: Restrict local OS access and file permissions on Armatura One backup and restore logs so low-privilege users cannot read them, and rotate the database superuser password if a backup or restore has already run. Search existing logs for database connection commands and remove or redact any stored passwords. Apply the vendor or CISA ICS advisory fix when a patched release is published; no fixed version is identified in the available data.
Affected
| Armatura LLC Armatura One | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.