CVE-2026-18717
nicheImproper TLS Certificate Validation in Applied Systems Engineering ASE2000
ASE2000 versions 2.35 through 2.37, a communications test set used in utility SCADA and RTU work, fails to properly validate TLS certificates when connecting to a trusted peer (CWE-295). An attacker positioned on the network path between the ASE2000 station and its peer can present an untrusted certificate during the TLS handshake; because validation is improper, the handshake completes and the attacker is accepted as the trusted peer. This allows the attacker to read and modify the protected communications, a high-impact confidentiality and integrity issue reflected in the critical CVSS 4.0 score of 9.1. Any site running ASE2000 2.35-2.37 is affected, though exploitation requires an on-path position and the attack is rated high complexity, with no privileges or user interaction needed. No public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS currently assigns only a 0.2% probability of exploitation within 30 days.
What to do: Upgrade ASE2000 to a release newer than 2.37 per the CISA ICS-CERT advisory and the vendor's release notes, since no fixed version number is stated in the available data. Until patched, run ASE2000 2.35-2.37 only on trusted, isolated network segments and avoid TLS-protected connections across shared, routed, or wireless networks where an on-path attacker could interpose. Because exploitation requires intercepting the communication path, network segmentation and access controls around test-set workstations are effective interim mitigations.
| Applied Systems Engineering (ASE) ASE2000 | 2.35 through 2.37 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
- Weakness
- CWE-295
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.