CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-94591: Armatura One 0 to before 4.7.2; +1 more affected products

CVE-2026-94591. CVSS 3.1 base score 8.4 (HIGH, Vendor/CNA). EPSS 0.00087 (percentile 0.00319), scored 03-Oct-2026.

Affected technology

Armatura One · 0 to before 4.7.2
Armatura LLC

Armatura One (USA) · 0 to before 4.6.1
Armatura LLC

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · No user interaction required

What an attacker can do

An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file. Vendor/CNA’s CVSS 4.0 assessment (base score 8.6/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-321
CCR priority
33.6 /100 (P4)
CVSS 3.1
8.4 /10 · CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00087 · percentile 0.00324 · 2026-10-10
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-94591.html