Executive brief
Armiya Information Technologies' Access Control System (GKS), which is used to manage physical security and entry points, contains a security flaw that allows unauthorized access to sensitive data. An attacker can remotely collect information from the system's internal storage locations without needing a username or password. This could lead to the exposure of personnel records, access logs, or other sensitive operational data, potentially compromising the physical security of the facility.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Armiya Information Technologies Access Control System (GKS) prior to Version 2. The flaw allows an unauthenticated attacker to access and collect data from common resource locations via the network. With a CVSS score of 8.2, the vulnerability is characterized by a low attack complexity and requires no user interaction or privileges. Successful exploitation results in high confidentiality impact, allowing the retrieval of sensitive system or user data. Users are advised to upgrade to Version 2 or later to remediate this issue.
Affected products
- Armiya Information Technologies Ltd. Co. Access Control System (GKS) before Version 2
Timeline
- 2026-07-07: advisory
- 2026-07-07: disclosed