Junglewise Threat Intelligence

CVE-2026-90647: ASE/Kalkitech ASE2000 V2 improper certificate validation in IEC 60870-5-104

CVE-2026-90647 · Severity: high · CVSS 7.4 · Published 2026-09-12

Executive brief

The ASE2000 V2 Communication Test Set is industrial equipment used for testing IEC 60870-5-104 power systems communications. A flaw in the TLS client allows attackers on the network to bypass certificate validation through forged or malicious certificates, enabling them to intercept and modify communications between systems without detection.

Technical details

The vulnerability is an improper certificate validation issue in the IEC 60870-5-104 TLS client component running in Task Mode on Windows. An attacker positioned on the network can present a certificate with multiple simultaneous validation faults that are not properly rejected by the application. This enables a Man-in-the-Middle (MITM) attack on TLS-protected communications. The vulnerability affects versions 2.35 through 2.37. No authentication or user interaction is required; exploitation requires only network-level access and the ability to intercept traffic.

Affected products

  • ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37

Timeline

  • 2026-09-12: disclosed

References