Applied Systems Engineering ASE2000 V2 Communications Test Set
CISA warns ASE2000 V2 test sets allow arbitrary file read/write, outbound request abuse, and TLS peer impersonation; version 2.38 fixes both vulnerabilities.
CISA published ICS advisory ICSA-26-239-04 for Applied Systems Engineering (Kalkitech) ASE2000 V2 Communications Test Set versions 2.25 through 2.37. Exploitation could allow reading or writing arbitrary local files, forcing outbound network requests, or intercepting the TLS connection to impersonate the trusted peer and read or modify protected communications. Vendor ASE/Kalkitech provides upgraded version 2.38, which also updates the bundled log4net library, fixing both vulnerabilities; customers are advised to upgrade.
- ASE2000 V2 versions 2.25 through 2.37 are affected
- Flaws enable arbitrary file read/write and TLS trusted-peer impersonation
- Upgrade to version 2.38 fixes both flaws and refreshes bundled log4net
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 >=2.25| =2.25| =2.25|<=2.37 Product Status: known_affected Remediations Mitigation ASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.38. In version 2.38 the bundled log4net library…
This source does not provide full text. Read it at cisa.gov.