VYPR
advisoryPublished Aug 27, 2026· 1 source

CISA Alerts to Critical Vulnerabilities in Applied Systems Engineering ASE2000 V2

CISA has identified two critical vulnerabilities in Applied Systems Engineering's ASE2000 V2 Communications Test Set, versions 2.25 through 2.37, potentially allowing attackers to compromise sensitive industrial control systems.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory detailing two significant vulnerabilities affecting the Applied Systems Engineering (ASE) ASE2000 V2 Communications Test Set. These flaws, identified as CVE-2018-1285 and CVE-2026-18717, impact versions 2.25 through 2.37 of the widely used industrial test equipment.

CVE-2018-1285 is an XML External Entity (XXE) injection vulnerability. This flaw arises from the use of an outdated Apache log4net library that does not properly disable XML external entities when parsing configuration files. Attackers can exploit this by providing a crafted configuration file, enabling them to read or write arbitrary local files on the affected system. This could lead to unauthorized data access or modification, potentially impacting the integrity of test set operations.

The second vulnerability, CVE-2026-18717, is an improper certificate validation issue. This flaw allows an attacker to impersonate a trusted peer by completing a Transport Layer Security (TLS) handshake. Successful exploitation could enable attackers to intercept communications, read sensitive data, or modify the protected data stream, thereby compromising the confidentiality and integrity of the communications between the test set and other network devices.

These vulnerabilities carry severe implications, with CVSS v3.1 base scores of 9.8 (Critical) for CVE-2018-1285 and 7.4 (High) for CVE-2026-18717, and CVSS 4.0 scores of 9.2 and 9.1 respectively. The potential impacts include the ability for an attacker to read or write local files, initiate outbound network requests, and intercept or modify communications. The affected sectors include Chemical, Critical Manufacturing, Energy, and Water and Wastewater, with the equipment deployed globally.

Applied Systems Engineering, in conjunction with Kalkitech, has released version 2.38 of the ASE2000 V2 Communications Test Set, which addresses both vulnerabilities. The update includes an upgrade of the bundled log4net library to version 3.3.1.0 and corrects the IEC 60870-5-104 TLS client certificate validation logic. Customers are strongly advised to upgrade to version 2.38 or later to mitigate these risks.

Until an upgrade can be applied, CISA and ASE recommend several interim mitigation strategies. These include restricting write access to the ASE2000 installation directory and configuration files to only trusted administrators. Additionally, organizations should avoid using IEC 60870-5-104 over TLS across untrusted or shared networks. Placing ASE2000 hosts on an isolated, segmented network, reachable only by intended peers, and ensuring the host is protected by a network firewall are also recommended measures.

CISA has emphasized the critical nature of these vulnerabilities, urging all users of the affected ASE2000 V2 versions to apply the available patches or implement the recommended mitigations without delay. The widespread use of such test sets in critical infrastructure underscores the importance of timely security updates to prevent potential disruptions and data breaches.

Synthesized by Vypr AI