ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Certificate Validation in IEC 60870‑5‑104 TLS Client Allows MITM |
Sat, 12 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications. | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-12T22:38:16.637Z
Reserved: 2026-09-12T22:28:32.772Z
Link: CVE-2026-90647
No data.
Status : Received
Published: 2026-09-12T23:17:01.490
Modified: 2026-09-12T23:17:01.490
Link: CVE-2026-90647
No data.
OpenCVE Enrichment
Updated: 2026-09-13T00:15:03Z
Weaknesses