Applied Systems Engineering ASE2000 V2 Communications Test Set
Brief
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications.
The following versions of Applied Systems Engineering ASE2000 V2 Communications Test Set are affected: ASE2000 =2. 25
- =2.25
- =2.25
- =2.37
Product Status:
known_affected Remediations Mitigation ASE/Kalkitech provides an upgraded version 2. 38 that fixes both vulnerabilities and customers are advised to upgrade to version 2.
- In version 2. 38 the bundled log4net library is upgraded to version 3.
- 1. 0, and the IEC 60870-5-104 TLS client certificate validation logic is corrected to ensure proper validation of certificate error conditions.
