<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>ASE2000 V2 Communications Test Set - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ase2000-v2-communications-test-set/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 16:05:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ase2000-v2-communications-test-set/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Applied Systems Engineering ASE2000 V2</title><link>https://feed.craftedsignal.io/briefs/2026-08-ase2000-vulnerabilities/</link><pubDate>Thu, 27 Aug 2026 16:05:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ase2000-vulnerabilities/</guid><description>Applied Systems Engineering ASE2000 V2 (versions 2.25-2.37) is affected by critical XXE and improper TLS validation vulnerabilities that allow for remote code execution, arbitrary file access, and man-in-the-middle attacks.</description><content:encoded><![CDATA[<p>Applied Systems Engineering (ASE) has disclosed critical security vulnerabilities affecting the ASE2000 V2 Communications Test Set, specifically versions 2.25 through 2.37. These flaws pose significant risks to industrial control environments, including the Energy, Chemical, and Water/Wastewater sectors. The vulnerabilities include an XML External Entity (XXE) injection flaw (CVE-2018-1285) due to an outdated log4net library, which enables local file read/write operations and potential arbitrary command execution. Additionally, a flaw in the IEC 60870-5-104 TLS implementation (CVE-2026-18717) allows for improper certificate validation, permitting attackers to impersonate trusted peers and intercept or modify sensitive industrial communications. Impacted organizations are urged to upgrade to version 2.38 immediately, which resolves both issues and updates the underlying log4net dependencies.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows unauthorized actors to read or write arbitrary local files, trigger malicious outbound network requests, and intercept encrypted communications via man-in-the-middle attacks. These capabilities jeopardize the integrity and availability of industrial processes globally, potentially leading to unauthorized control of communication streams or system compromise. Organizations relying on ASE2000 for critical infrastructure operations are at high risk if these systems remain internet-exposed or reside on untrusted, shared segments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of ASE2000 V2 to version 2.38 or later immediately to patch CVE-2018-1285 and CVE-2026-18717.</li>
<li>Restrict write access to the ASE2000 installation directory and configuration files to prevent the placement of malicious log4net configuration files used to trigger CVE-2018-1285.</li>
<li>Isolate hosts running ASE2000 into segmented networks with strict firewall controls, ensuring they are not reachable from the public internet or untrusted enterprise network segments.</li>
<li>Disable or avoid the use of IEC 60870-5-104 over TLS on networks where traffic cannot be fully trusted, pending system upgrades.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>