DoseFix LIVE
0votes
Security·United States·CONFIRMED

CISA Advisory: Critical Vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set

United States·
DoseFix EditorialMulti-source synthesis

CISA released an Industrial Control Systems advisory on August 27, 2026, detailing two vulnerabilities affecting the Applied Systems Engineering ASE2000 V2 Communications Test Set, versions 2.25 through 2.37. The first vulnerability, CVE-2018-1285, is an improper restriction of XML external entity reference (XXE) in the bundled Apache log4net library, allowing an attacker to read or write arbitrary local files or cause outbound network requests. The second, CVE-2026-18717, is an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client, allowing an attacker to impersonate a trusted peer, complete the TLS handshake, and read or modify protected communications. The CVSS scores range from 7.4 to 9.8 (critical). The vendor, ASE/Kalkitech, has released version 2.38 which upgrades log4net and corrects certificate validation. CISA recommends upgrading immediately and provides interim mitigations such as restricting write access, isolating networks, and using firewalls. No known public exploitation has been reported.

1 sources
United States

What we know

Product deployed worldwide in critical infrastructure sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater.

1 sources

Successful exploitation could allow arbitrary file read/write, outbound requests, or TLS interception.

1 sources

CISA published an advisory on 2026-08-27 for ASE2000 V2 Communications Test Set.

1 sources

CVE-2026-18717: Improper certificate validation in IEC 60870-5-104 TLS client.

1 sources

Vendor released version 2.38 to fix both vulnerabilities.

1 sources

CVE-2018-1285: XXE vulnerability in Apache log4net before 2.0.10.

1 sources

Affected versions: ASE2000 2.25 through 2.37.

1 sources

No known public exploitation reported.

1 sources
CISA Advisory Timeline

CISA published an advisory on August 27, 2026, disclosing two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set (versions 2.25 through 2.37). The vulnerabilities, CVE-2018-1285 (XXE) and CVE-2026-18717 (improper certificate validation), could allow attackers to read/write arbitrary files, issue outbound requests, or intercept and modify TLS-protected communications. The vendor has released version 2.38 to fix both issues. No public exploitation has been reported.

Verified · 1 sources

Live reports

View all
CISA Advisory TimelineLocal voice · United States
Verified

Comments 0

Discuss this event in persistent threads. Live chat remains separate.

Keep discussion civil and distinguish opinion from verified information.

No comments yet. Start the conversation.

CISA Advisory: Critical Vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set | DoseFix