← Back to Feed

Applied Systems Engineering ASE2000 V2 Communications Test Set

CVE-2018-1285CVE-2026-18717

August 27, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717) CVSS Vendor Equipment Vulnerabilities v3 9.8 Applied Systems Engineering Applied Systems Engineering ASE2000 V2 Communications Test Set Improper Restriction of XML External Entity Reference, Improper Certificate Validation Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2018-1285 ASE2000 versions 2.25 through 2.37 is vulnerable to Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE based attacks in applications that accept attacker controlled log4net configuration files. View CVE Details Affected Products Applied Systems Engineering ASE2000 V2 Communications Test Set Vendor:Applied Systems Engineering Product Version:Applied Systems Engineering ASE2000: >=2.25|<=2.37 Product Status:known_affected Remediations MitigationASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library is upgraded to version 3.3.1.0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions. Vendor fixAll customers running ASE2000 versions 2.25 through 2.37 are affected by this issue and are required to upgrade to version 2.38 or...

Key Takeaways

  • CISA published an advisory for Applied Systems Engineering ASE2000 V2 Communications Test Set urging users to apply vendor patches and mitigations.
  • Organizations using Applied Systems Engineering ASE2000 V2 Communications Test Set should review CISA's advisory and apply security updates promptly.
  • Active exploitation of vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set has been reported, making patching urgent for affected organizations.
☕ Buy a Coffee