CISA published an ICS advisory for two vulnerabilities in Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37. CVE-2018-1285 is a critical XXE vulnerability in the bundled Apache log4net library that could allow arbitrary file read/write and outbound network requests. CVE-2026-18717 is a high-severity improper certificate validation flaw in the IEC 60870-5-104 TLS client that enables man-in-the-middle attacks. The vendor recommends upgrading to version 2.38, which remediates both issues.
CVE-2018-1285
1 post
Applied Systems Engineering ASE2000 V2 Communications Test Set (CVE-2018-1285, CVE-2026-18717)