CISA Flags ASE2000 Test Set Trust Flaws

CISA warned that Applied Systems Engineering’s ASE2000 V2 Communications Test Set has two vulnerabilities affecting versions 2.25 through 2.37, with the fixed release at 2.38. The advisory says the product is deployed worldwide across critical infrastructure, including energy. The first flaw is an XML external entity issue in bundled log4net code: crafted configuration files can make the software read local files or reach out to outside systems. The second flaw is in TLS certificate handling for IEC 60870-5-104, where bad validation can let an attacker impersonate the trusted peer and read or alter protected communications. For OT and ICS environments, the exposure is bigger than one workstation because this test set may sit in validation workflows that decide whether communications are trusted. Where ASE2000 V2 is part of those checks, the risk is not just file access but a break in the trust layer that protects operational traffic.

Part of the PlainSec briefing for 2026-08-27

Every edition of this story: CISA Flags ASE2000 Test Set Trust Flaws

CVEs

Sources