Applied Systems Engineering ASE2000 V2 Communications Test Set
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717) CVSS Vendor Equipment Vulnerabilities v3 9.8 Applied Systems Engineering Applied Systems Engineering ASE2000 V2 Communications Test Set Improper Restriction of XML External Entity Reference, Improper Certificate Validation Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2018-1285 ASE2000 versions 2.25 through 2.37 is vulnerable to Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE based attacks in applications that accept attacker controlled log4net configuration files. View CVE Details Affected Products Applied Systems Engineering ASE2000 V2 Communications Test Set Vendor: Applied Systems Engineering Product Version: Applied Systems Engineering ASE2000: >=2.25|<=2.37 Product Status: known_affected Remediations Mitigation ASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library is upgraded to version 3.3.1.0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions. Vendor fix All customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or later to apply the security fix. Up
CSIRTS triage
- What
- XXE (XML External Entity) injection and improper certificate validation allow file read/write, outbound requests, and TLS impersonation.
- Who is affected
- Deployments running ASE2000 V2 versions 2.25–2.37 processing XML or establishing TLS connections.
- Urgency
- Critical; these flaws enable reading/writing files and intercepting protected communications in industrial environments.
- Action
- Upgrade ASE2000 V2 Communications Test Set to a version above 2.37.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ASE2000 V2 Communications Test Set
Get an email when a new ASE2000 V2 Communications Test Set advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2018-128517.4% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-187170.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2018-1285 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18717 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CISA Cybersecurity Advisories
- criticalOrthanc DICOM Server2026-09-10
- criticalNextGen Healthcare Mirth Connect2026-09-10
- criticalCISA Adds Two Known Exploited Vulnerabilities to Catalog2026-09-10
- criticalAVEVA Pipeline Integrity Monitor2026-09-10
- criticalST Engineering iDirect iQ-Series Terminals (Update A)2026-09-10