Security & Threat Intelligence · 27.08.2026, 15:48 UTC
Applied Systems Engineering ASE2000 V2 Communications Test Set
| Schweregrad | info |
|---|---|
| CVE | ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 27.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2018-1285, CVE-2026-18717. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected:
ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717)
CVSS Vendor Equipment Vulnerabilities
v3 9.8 Applied Systems Engineering Applied Systems Engineering ASE2000 V2 Communications Test Set Improper Restriction of XML External Entity Reference, Improper Certificate Validation
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2018-1285
ASE2000 versions 2.25 through 2.37 is vulnerable to Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE based attacks in applications that accept attacker controlled log4net configuration files. View CVE Details
Affected Products Applied Systems Engineering ASE2000 V2 Communications Test Set
Vendor:Applied Systems Engineering Product Version:Applied Systems Engineering ASE2000: >=2.25|<=2.37 Product Status:known_affected
Remediations MitigationASE/Kalkitech provides an upgraded version 2.38 that fixes both vulnerabilities and customers are advised to upgrade …