CISA Advisory: Critical Vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set
CISA released an Industrial Control Systems advisory on August 27, 2026, detailing two vulnerabilities affecting the Applied Systems Engineering ASE2000 V2 Communications Test Set, versions 2.25 through 2.37. The first vulnerability, CVE-2018-1285, is an improper restriction of XML external entity reference (XXE) in the bundled Apache log4net library, allowing an attacker to read or write arbitrary local files or cause outbound network requests. The second, CVE-2026-18717, is an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client, allowing an attacker to impersonate a trusted peer, complete the TLS handshake, and read or modify protected communications. The CVSS scores range from 7.4 to 9.8 (critical). The vendor, ASE/Kalkitech, has released version 2.38 which upgrades log4net and corrects certificate validation. CISA recommends upgrading immediately and provides interim mitigations such as restricting write access, isolating networks, and using firewalls. No known public exploitation has been reported.
What we know
Product deployed worldwide in critical infrastructure sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater.
▤ 1 sources›
Successful exploitation could allow arbitrary file read/write, outbound requests, or TLS interception.
▤ 1 sources›
CISA published an advisory on 2026-08-27 for ASE2000 V2 Communications Test Set.
▤ 1 sources›
CVE-2026-18717: Improper certificate validation in IEC 60870-5-104 TLS client.
▤ 1 sources›
Vendor released version 2.38 to fix both vulnerabilities.
▤ 1 sources›
CVE-2018-1285: XXE vulnerability in Apache log4net before 2.0.10.
▤ 1 sources›
Affected versions: ASE2000 2.25 through 2.37.
▤ 1 sources›
No known public exploitation reported.
▤ 1 sources›
CISA published an advisory on August 27, 2026, disclosing two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set (versions 2.25 through 2.37). The vulnerabilities, CVE-2018-1285 (XXE) and CVE-2026-18717 (improper certificate validation), could allow attackers to read/write arbitrary files, issue outbound requests, or intercept and modify TLS-protected communications. The vendor has released version 2.38 to fix both issues. No public exploitation has been reported.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.