Applied Systems Engineering ASE2000 V2 Communications Test Set
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-04.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.</strong></p>
<p>The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected:</p>
<ul>
<li>ASE2000 >=2.25|<=2.37 (CVE-2018-1285, CVE-2026-18717)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 9.8</td>
<td>Applied Systems Engineering</td>
<td>Applied Systems Engineering ASE2000 V2 Communications Test Set</td>
<td>Improper Restriction of XML External Entity Reference, Improper Certificate Validation</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Chemical, Critical Manufacturing, Energy, Water and Wastewater</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>United States</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="#">CVE-2018-1285</a></h3>
<div class="csaf-accordion-content">
<p>ASE2000 versions 2.25 through 2.37 is vulnerable to Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. T
CRITICAL
Severity & confidence
Source severitycritical
Platform severitycritical
Confidencehigh
Exploitationunknown
CVSS-
Affected
Reporting sources (1)
CISA - Cybersecurity Advisories
Timeline & provenance
Published2026-08-27T16:44:24
Last updated2026-09-06T05:34:34
Ingested2026-08-27T16:44:24
FreshnessNEAR-REAL-TIME
Threat typephishing
Recommended action
No recommended action published with this item - review the original source.
Next steps
- Identify affected systems in your environment.
- Apply the vendor patch or mitigation guidance.
- Review logs for indicators described in the advisory.
- Follow the affected vendor/product to track updates.
Confidence explanation
Reported by a government or cert-grade source (CISA, NCSC, NVD, ENISA, MSRC).
Source type: gov ยท Original: CISA - Cybersecurity Advisories