CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Applied Systems Engineering ASE2000 V2 Communications Test Set

criticalCVE-2018-1285CVE-2026-18717
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717) CVSS Vendor Equipment Vulnerabilities v3 9.8 Applied Systems Engineering Applied Systems Engineering ASE2000 V2 Communications Test Set Improper Restriction of XML External Entity Reference, Improper Certificate Validation Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2018-1285 ASE2000 versions 2.25 through 2.37 is vulnerable to Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE based attacks in applications that accept attacker controlled log4net configuration files. View CVE Details Affected Products Applied Systems Engineering ASE2000 V2 Communications Test Set Vendor: Applied Systems Engineering Product Version: Applied Systems Engineering ASE2000: >=2.25|<=2.37 Product Status: known_affected Remediations Mitigation ASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library is upgraded to version 3.3.1.0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions. Vendor fix All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Up

CSIRTS triage

What
XXE (XML External Entity) injection and improper certificate validation allow file read/write, outbound requests, and TLS impersonation.
Who is affected
Deployments running ASE2000 V2 versions 2.25–2.37 processing XML or establishing TLS connections.
Urgency
Critical; these flaws enable reading/writing files and intercepting protected communications in industrial environments.
Action
Upgrade ASE2000 V2 Communications Test Set to a version above 2.37.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch ASE2000 V2 Communications Test Set

Get an email when a new ASE2000 V2 Communications Test Set advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-27
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2018-1285coverage & exploitation statusNVD · CVE.org
CVE-2026-18717coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories