CVE-2026-90647
nicheTLS Certificate Validation Bypass in ASE2000 V2 IEC 60870-5-104 Client Allows MITM
ASE/Kalkitech ASE2000 V2 Communication Test Set versions 2.35 through 2.37 on Windows performs improper certificate validation in its IEC 60870-5-104 TLS client when operating in Task Mode. A network-positioned attacker can present a certificate carrying multiple simultaneous faults (for example one that is both expired and self-signed), and the flawed validation logic will accept it, allowing the attacker to impersonate the legitimate 60870-5-104 server. Successful exploitation enables a man-in-the-middle who can read and modify supposedly protected SCADA telecontrol traffic, including measured values, credentials, and control commands exchanged during testing. Affected users are utilities, system integrators, and engineers running the Windows test set against TLS-protected IEC 60870-5-104 endpoints. No public proof-of-concept exists, there is no confirmed in-the-wild exploitation, and the CVE is not on the CISA KEV list.
What to do: Upgrade to a release newer than 2.37 as soon as ASE/Kalkitech makes one available; contact the vendor if patch availability is unclear. Until patched, treat TLS-protected IEC 60870-5-104 sessions made with the tool in Task Mode as potentially interceptable: run it only on trusted, segmented engineering networks and never across untrusted links. Additionally, use host firewall rules to restrict which 60870-5-104 servers the test set can reach, and review critical test sessions for signs of interception.
| ASE / Kalkitech ASE2000 V2 Communication Test Set | 2.35 through 2.37 (Windows) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
- Weakness
- CWE-295
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.