CVE-2026-18717: Improper Certificate Validation in ASE 2000
ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ASE2000to a version that resolves this vulnerability.Fixed in 2.38 - Upgrade
Upgrade
ASE2000 (bundled log4net library)to a version that resolves this vulnerability.Fixed in 3.3.1.0 - Configuration
After upgrading to ASE2000 version 2.38 (or later), ensure the IEC 60870-5-104 TLS client certificate validation logic correctly validates certificate error conditions to prevent improper certificate validation.
IEC 60870-5-104 TLS client certificate validation logic (in ASE 2000) certificate validation of certificate error conditions = corrected to ensure proper validation
Event History
Frequently Asked Questions
Which deployments are affected?
ASE2000 versions 2.35 through 2.37 are affected. The provided information does not identify unaffected versions or configuration-specific limitations.
What must an attacker be able to do to exploit this issue?
An attacker must be able to impersonate a trusted peer during a TLS connection. Successful exploitation allows the attacker to complete the TLS handshake and read or modify communications that should be protected.
Does exploitation require credentials or user interaction?
No. The supplied CVSS vector indicates no privileges are required and no user interaction is required, although attack complexity is rated high.