ZeroHour

CVE-2026-90647

niche

TLS Certificate Validation Bypass in ASE2000 V2 IEC 60870-5-104 Client Allows MITM

CVSS 4.0
9.1 critical
EPSS
Published
()
Modified
AI analysis

ASE/Kalkitech ASE2000 V2 Communication Test Set versions 2.35 through 2.37 on Windows performs improper certificate validation in its IEC 60870-5-104 TLS client when operating in Task Mode. A network-positioned attacker can present a certificate carrying multiple simultaneous faults (for example one that is both expired and self-signed), and the flawed validation logic will accept it, allowing the attacker to impersonate the legitimate 60870-5-104 server. Successful exploitation enables a man-in-the-middle who can read and modify supposedly protected SCADA telecontrol traffic, including measured values, credentials, and control commands exchanged during testing. Affected users are utilities, system integrators, and engineers running the Windows test set against TLS-protected IEC 60870-5-104 endpoints. No public proof-of-concept exists, there is no confirmed in-the-wild exploitation, and the CVE is not on the CISA KEV list.

What to do: Upgrade to a release newer than 2.37 as soon as ASE/Kalkitech makes one available; contact the vendor if patch availability is unclear. Until patched, treat TLS-protected IEC 60870-5-104 sessions made with the tool in Task Mode as potentially interceptable: run it only on trusted, segmented engineering networks and never across untrusted links. Additionally, use host firewall rules to restrict which 60870-5-104 servers the test set can reach, and review critical test sessions for signs of interception.

Affected
ASE / Kalkitech ASE2000 V2 Communication Test Set2.35 through 2.37 (Windows)
Estimated exposure
nichelikely low thousands of installations worldwide (estimate) — ASE2000 is a specialist commercial protocol test instrument used mainly by electric utilities, SCADA integrators, and protection-and-control equipment vendors, and no public install counts or internet-exposed service data exist for it.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.

Weakness
CWE-295
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.