criticalOther

Applied Systems Engineering ASE2000 V2 Communications Test Set - XXE and Improper Certificate Validation Vulnerabilities

First seen Aug 30, 2026 · Updated Aug 30, 2026 · CVSS 9.8

icsscadaxxetlscertificate-validationlog4netiec-60870-5-104critical-infrastructure

ASE2000 V2 Communications Test Set versions 2.25 through 2.37 contain two vulnerabilities: an XML External Entity (XXE) flaw inherited from a bundled outdated Apache log4net library, and an improper TLS certificate validation flaw affecting IEC 60870-5-104 secure communications. Successful exploitation could allow attackers to read/write arbitrary local files, trigger outbound network requests, or perform man-in-the-middle attacks to intercept and modify protected substation/grid communications.

Technical Analysis

CVE-2018-1285 stems from a bundled Apache log4net version prior to 2.0.10 that fails to disable XML external entities when parsing attacker-controlled log4net configuration files, enabling classic XXE attacks (CWE-611) with a CVSS v3.1 score of 9.8. CVE-2026-18717 (CWE-295, CVSS v3.1 7.4 / CVSS v4.0 9.1) affects the IEC 60870-5-104 TLS client certificate validation logic in versions 2.35-2.37, allowing an attacker positioned on the network to impersonate a trusted peer, complete the TLS handshake, and read or tamper with protected ICS/SCADA telemetry and control traffic. Both issues are remotely exploitable without authentication or user interaction, and are remediated in ASE2000 version 2.38, which upgrades log4net to 3.3.1.0 and corrects certificate validation. This is an OT/ICS testing tool used in Chemical, Critical Manufacturing, Energy, and Water/Wastewater sectors, and while there is no direct AI agent tooling involved, organizations using AI-driven monitoring, automation, or agentic orchestration layered on top of ICS networks should ensure those systems do not trust or ingest unauthenticated data from affected ASE2000 hosts, as compromised TLS sessions or XXE-triggered outbound requests could be leveraged to feed manipulated data into automated/agentic decision pipelines.

Affected Systems

Applied Systems Engineering ASE2000 V2 Communications Test Set, versions >=2.25 and <=2.37 (CVE-2026-18717 specifically affects versions 2.35-2.37); deployed in IEC 60870-5-104 communication test environments across Chemical, Critical Manufacturing, Energy, and Water/Wastewater sectors worldwide.

Indicators of Compromise

  • No known IOCs published; no public exploitation reported by CISA at this time.

Remediation Steps

  1. 1

    Upgrade to ASE2000 version 2.38

    Apply the vendor-provided upgrade to version 2.38 or later, which updates the bundled log4net library to 3.3.1.0 and corrects the IEC 60870-5-104 TLS client certificate validation logic.

  2. 2

    Restrict configuration file access

    Limit write access to the ASE2000 installation directory and configuration files to trusted administrators only to reduce XXE attack surface.

  3. 3

    Isolate and segment ICS networks

    Avoid using IEC 60870-5-104 over TLS across untrusted or shared networks; place ASE2000 hosts on an isolated, segmented network reachable only by intended peers.

  4. 4

    Deploy network protections

    Ensure ASE2000 hosts are protected by a network firewall and are not accessible from the internet; place control system networks behind firewalls separate from business networks.

  5. 5

    Use secure remote access

    When remote access is required, use VPNs kept updated to current versions, recognizing that VPN security depends on the security of connected devices.

CVE / Advisory IDs

CVE-2018-1285CVE-2026-18717

Industries Most Exposed

ChemicalCritical ManufacturingEnergyWater and Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.