CISA flags ASE2000 XXE and TLS validation flaws
ASE2000 V2 Communications Test Set versions 2.25–2.37 have XXE and TLS certificate validation flaws; vendor advises upgrading to 2.38.
CISA published an ICS advisory for Applied Systems Engineering's (ASE/Kalkitech) ASE2000 V2 Communications Test Set, a tool used in energy, water/wastewater, chemical, and critical manufacturing sectors worldwide. Two vulnerabilities affect versions 2.25 through 2.37: CVE-2018-1285, a known XML External Entity (XXE) issue in the bundled Apache log4net library (versions before 2.0.10) that fails to disable external entity resolution when parsing log4net configuration files, potentially allowing arbitrary local file read/write and outbound network requests; and CVE-2026-18717, an improper TLS certificate validation flaw in the IEC 60870-5-104 client that could let an attacker impersonate a trusted peer, complete the TLS handshake, and read or modify protected communications.
Both issues stem from outdated/mishandled third-party components rather than novel exploitation research, and CISA states no known public exploitation has been reported. The vendor has released version 2.38, which upgrades log4net to 3.3.1.0 and corrects the TLS certificate validation logic for IEC 60870-5-104. Until upgraded, CISA and the vendor recommend restricting write access to the ASE2000 installation directory, avoiding use of IEC 60870-5-104 over TLS on untrusted/shared networks, network segmentation, and standard ICS network isolation practices (no direct internet exposure, firewalls, VPN use for remote access).
This is a routine vendor-patched ICS advisory affecting a niche communications test set used with substation/RTU protocol testing. Impact is limited to organizations running the affected software versions in operational technology environments; risk is elevated primarily through network exposure or use of untrusted TLS-protected links, both of which are mitigated by the vendor's upgrade and CISA's standard segmentation guidance.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free