CVE-2026-90647: High severity Kalkitech ASE2000 V2 Communication Test Set vulnerability
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for investigation?
Prioritize Windows systems running ASE2000 V2 Communication Test Set versions 2.35 through 2.37 when they use the IEC 60870-5-104 TLS client in Task Mode. The issue concerns certificate validation for protected communications in that client.
What access does an attacker need to exploit this issue?
An attacker must be positioned on the network path between the client and its intended peer. No privileges or user interaction are required, but exploitation has high attack complexity because the attacker needs a certificate with multiple simultaneous faults.
What could an attacker accomplish if exploitation succeeds?
A successful attacker can bypass certificate validation and conduct a man-in-the-middle attack on protected communications. The stated impact includes high confidentiality and integrity impact, with no availability impact.