Applied Systems Engineering ASE2000 V2 Communications Test Set

Act NowCVSS 9.8ICS-CERT ICSA-26-239-04Aug 27, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

ASE2000 V2 versions 2.25 through 2.37 contain two critical vulnerabilities: XML external entity (XXE) injection via the log4net library (CWE-611) and missing TLS certificate validation in IEC 60870-5-104 client connections (CWE-295). These flaws allow remote attackers to read or write arbitrary files, trigger server-side request forgery (SSRF), or intercept and modify encrypted communications with connected devices. The log4net vulnerability stems from improper handling of XML input, while the IEC 60870-5-104 flaw fails to properly validate certificate error conditions, allowing man-in-the-middle attacks on secure channels. Both vulnerabilities require only network access and no authentication.

What this means
What could happen
An attacker with network access could read or modify files on the ASE2000 system, intercept and alter communications with connected devices, or force the system to make unauthorized outbound network requests. This could compromise the integrity of process data or allow command injection into connected IEC 60870-5-104 devices.
Who's at risk
Water utilities, electric utilities, and other critical infrastructure operators using Applied Systems Engineering ASE2000 V2 Communications Test Set for IEC 60870-5-104 protocol testing and SCADA communications. This affects remote terminal units (RTUs), substations, and generation facilities that rely on ASE2000 for device communications or network testing.
How it could be exploited
An attacker on the network sends a specially crafted request to ASE2000 to trigger XML external entity (XXE) injection or exploits missing TLS certificate validation. The attacker can then read local files, perform server-side request forgery (SSRF) to issue outbound requests, or intercept IEC 60870-5-104 TLS communications by presenting a forged certificate, allowing modification of control commands before they reach downstream devices.
Prerequisites
  • Network access to ASE2000 system
  • IEC 60870-5-104 over TLS enabled (for certificate validation bypass)
  • No authentication required for XXE or SSRF exploitation
remotely exploitableno authentication requiredlow complexityhigh EPSS score (17.4%)affects SCADA/IEC 60870-5-104 communicationscan compromise process integrity and control
Exploitability
Likely to be exploited — EPSS score 17.4%
Public Proof-of-Concept (PoC) on GitHub (1 repository)
Affected products (1)
ProductAffected VersionsFix Status
ASE2000: >=2.25|<=2.37≥ 2.25|≤ 2.372.38
Remediation & Mitigation
0/5
Do now
0/3
WORKAROUNDRestrict network access to ASE2000 to trusted peers only using firewall rules
WORKAROUNDDisable or avoid using IEC 60870-5-104 over TLS until upgrade is applied
HARDENINGRestrict write access to ASE2000 installation directory and configuration files to authorized administrators only
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpgrade ASE2000 to version 2.38 or later
Long-term hardening
0/1
HARDENINGPlace ASE2000 on a segmented network isolated from untrusted or shared networks
API: /api/v1/advisories/976356de-e168-4c85-87ef-f3e59ba2d051

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.