DoseFix LIVE
0votes
Security·United States·CONFIRMED

CISA Advisory: Critical Vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set

United States·
DoseFix EditorialMulti-source synthesis

CISA released an Industrial Control Systems advisory on August 27, 2026, detailing two vulnerabilities affecting the Applied Systems Engineering ASE2000 V2 Communications Test Set, versions 2.25 through 2.37. The first vulnerability, CVE-2018-1285, is an improper restriction of XML external entity reference (XXE) in the bundled Apache log4net library, allowing an attacker to read or write arbitrary local files or cause outbound network requests. The second, CVE-2026-18717, is an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client, allowing an attacker to impersonate a trusted peer, complete the TLS handshake, and read or modify protected communications. The CVSS scores range from 7.4 to 9.8 (critical). The vendor, ASE/Kalkitech, has released version 2.38 which upgrades log4net and corrects certificate validation. CISA recommends upgrading immediately and provides interim mitigations such as restricting write access, isolating networks, and using firewalls. No known public exploitation has been reported.

1 sources
United States

What we know

Product deployed worldwide in critical infrastructure sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater.

1 sources

Successful exploitation could allow arbitrary file read/write, outbound requests, or TLS interception.

1 sources

CISA published an advisory on 2026-08-27 for ASE2000 V2 Communications Test Set.

1 sources

CVE-2026-18717: Improper certificate validation in IEC 60870-5-104 TLS client.

1 sources

Vendor released version 2.38 to fix both vulnerabilities.

1 sources

CVE-2018-1285: XXE vulnerability in Apache log4net before 2.0.10.

1 sources

Affected versions: ASE2000 2.25 through 2.37.

1 sources

No known public exploitation reported.

1 sources
Source transparency

Open any source to inspect its original language, when DoseFix received it, and the claims it supports.

CISA Cybersecurity Advisories

Applied Systems Engineering ASE2000 V2 Communications Test Set

cisa.gov · EN · Published · Received
Independent

Live reports

View all
CISA Advisory TimelineLocal voice · United States
Verified

Comments 0

Discuss this event in persistent threads. Live chat remains separate.

Keep discussion civil and distinguish opinion from verified information.

No comments yet. Start the conversation.