Impact
The vulnerability is an improper certificate validation flaw (CWE-295) in the IEC 60870‑5‑104 Task Mode TLS client of the ASE2000 V2 Communication Test Set. A device positioned on the network can supply a certificate containing multiple simultaneous faults, leading the client to accept it and establish TLS sessions without proper validation. This flaw enables a malicious actor to perform a Man‑in‑the‑Middle attack on protected communications, potentially compromising confidentiality and integrity of the monitored processes.
Affected Systems
Kalkitech’s ASE2000 V2 Communication Test Set software versions 2.35 through 2.37 running on Windows is affected. Users of these specific firmware releases should verify the installed version and consult the vendor advisory.
Risk and Exploitability
The CVSS score of 9.1 signals a critical threat. The EPSS score is <1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack is feasible from any position that can present a forged TLS certificate to the client, making MITM possible without additional constraints.
OpenCVE Enrichment