{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ofedoraprojectfedora30/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:log4net:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*","cpe:2.3:a:oracle:hospitality_opera_5:5.5:*:*:*:*:*:*:*","cpe:2.3:a:oracle:hospitality_opera_5:5.6:*:*:*:*:*:*:*","cpe:2.3:a:oracle:hospitality_simphony:18.2.7.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:hospitality_simphony:19.1.3:*:*:*:*:*:*:*","cpe:2.3:a:netapp:manageability_software_development_kit:-:*:*:*:*:*:*:*","cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2018-1285"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ASE2000 V2 Communications Test Set"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Applied Systems Engineering"],"content_html":"\u003cp\u003eApplied Systems Engineering (ASE) has disclosed critical security vulnerabilities affecting the ASE2000 V2 Communications Test Set, specifically versions 2.25 through 2.37. These flaws pose significant risks to industrial control environments, including the Energy, Chemical, and Water/Wastewater sectors. The vulnerabilities include an XML External Entity (XXE) injection flaw (CVE-2018-1285) due to an outdated log4net library, which enables local file read/write operations and potential arbitrary command execution. Additionally, a flaw in the IEC 60870-5-104 TLS implementation (CVE-2026-18717) allows for improper certificate validation, permitting attackers to impersonate trusted peers and intercept or modify sensitive industrial communications. Impacted organizations are urged to upgrade to version 2.38 immediately, which resolves both issues and updates the underlying log4net dependencies.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows unauthorized actors to read or write arbitrary local files, trigger malicious outbound network requests, and intercept encrypted communications via man-in-the-middle attacks. These capabilities jeopardize the integrity and availability of industrial processes globally, potentially leading to unauthorized control of communication streams or system compromise. Organizations relying on ASE2000 for critical infrastructure operations are at high risk if these systems remain internet-exposed or reside on untrusted, shared segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of ASE2000 V2 to version 2.38 or later immediately to patch CVE-2018-1285 and CVE-2026-18717.\u003c/li\u003e\n\u003cli\u003eRestrict write access to the ASE2000 installation directory and configuration files to prevent the placement of malicious log4net configuration files used to trigger CVE-2018-1285.\u003c/li\u003e\n\u003cli\u003eIsolate hosts running ASE2000 into segmented networks with strict firewall controls, ensuring they are not reachable from the public internet or untrusted enterprise network segments.\u003c/li\u003e\n\u003cli\u003eDisable or avoid the use of IEC 60870-5-104 over TLS on networks where traffic cannot be fully trusted, pending system upgrades.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T16:05:01Z","date_published":"2026-08-27T16:05:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ase2000-vulnerabilities/","summary":"Applied Systems Engineering ASE2000 V2 (versions 2.25-2.37) is affected by critical XXE and improper TLS validation vulnerabilities that allow for remote code execution, arbitrary file access, and man-in-the-middle attacks.","title":"Critical Vulnerabilities in Applied Systems Engineering ASE2000 V2","url":"https://feed.craftedsignal.io/briefs/2026-08-ase2000-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}