Applied Systems Engineering ASE2000 V2 Communications Test Set
ASE2000 V2 versions 2.25 through 2.37 contain two critical vulnerabilities: XML external entity (XXE) injection via the log4net library (CWE-611) and missing TLS certificate validation in IEC 60870-5-104 client connections (CWE-295). These flaws allow remote attackers to read or write arbitrary files, trigger server-side request forgery (SSRF), or intercept and modify encrypted communications with connected devices. The log4net vulnerability stems from improper handling of XML input, while the IEC 60870-5-104 flaw fails to properly validate certificate error conditions, allowing man-in-the-middle attacks on secure channels. Both vulnerabilities require only network access and no authentication.
- Network access to ASE2000 system
- IEC 60870-5-104 over TLS enabled (for certificate validation bypass)
- No authentication required for XXE or SSRF exploitation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/976356de-e168-4c85-87ef-f3e59ba2d051Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.