Impact
ASE2000 versions 2.35 through 2.37 allow the IEC 60870-5-104 TLS client to accept certificates without proper validation, enabling an attacker to impersonate a trusted peer. The attacker can then complete the TLS handshake and read or modify protected communications. This flaw directly compromises the confidentiality and integrity of data exchanged over the protocol.
Affected Systems
The vulnerability affects Applied Systems Engineering ASE2000 version 2.25 through 2.37. Customers using these releases must upgrade to version 2.38 or later, which includes an updated log4net library and corrected TLS client certificate validation logic.
Risk and Exploitability
With a CVSS score of 9.1, the flaw is considered critical. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers would need to target the IEC 60870-5-104 channel over TLS, which is likely to be over an untrusted or shared network. The vulnerability can be exploited without external credentials, so the exploitability is high.
OpenCVE Enrichment