AI analysis
Armatura One’s message broker writes client connection credentials, including the associated password, to logs in plain text during normal operation (CWE-532). Anyone who can read those logs, or a backup or support bundle that contains them, can recover the logged credential without needing a separate exploit. Impact is limited to confidentiality of the logged secret (CVSS 4.0 base 5.1, local access, low confidentiality). The issue affects Armatura LLC’s Armatura One; the advisory data does not name a version range. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Restrict read access to Armatura One message-broker logs, backups, and support bundles, and treat any client connection passwords that may have been written there as exposed and rotate them. Do not share support bundles that include those logs until the vendor confirms logging of credentials has been removed. No fixed version is identified in the advisory data, so follow Armatura’s published guidance when a patch is available.
Affected
| Armatura LLC Armatura One | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this log, or to a backup or support bundle that includes it, can obtain the logged credential.