CCISA AdvisoriesinVulnerability·critical
Critical Vulnerabilities Discovered in Applied Systems Engineering ASE2000 V2 Communications Test Set
CISA has issued an industrial control systems advisory detailing two vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set. CVE-2018-1285 is an XXE vulnerability in the bundled log4net library that could allow arbitrary file read/write. CVE-2026-18717 is an improper certificate validation flaw that could permit TLS handshake interception and modification. Affected versions range from 2.25 to 2.37. ASE/Kalkitech has released version 2.38 addressing both issues.
11m