CVE-2026-90647
ASE/Kalkitech ASE2000 V2 Communication Test Set versions 2.35 through 2.37 for Windows have a flaw that lets a network attacker bypass TLS certificate checks in the IEC 60870-5-104 client. This flaw can be used to intercept or alter protected communications. The issue is critical because it undermines the security of the entire communication channel.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35, 2.36, and 2.37 running on Windows.
Real-world impact
An attacker positioned on the network can trick the device into trusting a forged certificate, allowing them to eavesdrop on, modify, or inject data into the protected communication stream.
Why this severity
The CVSS score of 9.1 reflects the high impact on confidentiality and integrity of the data being transmitted, combined with the fact that the vulnerability can be exploited remotely without authentication or user interaction.
What to do about it
- ›Avoid using the affected ASE2000 V2 Communication Test Set versions until a vendor patch is released.
- ›If possible, disable TLS or use an alternative communication method that does not rely on the vulnerable client.
- ›Monitor network traffic for signs of a man‑in‑the‑middle attack and isolate the device if suspicious activity is detected.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources