Skip to content
  • NVDA
  • AAPL
  • MSFT
  • AMD
  • TSLA

CISA Warns of Critical Flaws in ASE2000 V2 Test Set

Advisory highlights risks of file read/write, outbound requests, and TLS interception.

By TMRO Staff·1 min read

Key points

  • CISA advisory published 2026-08-27
  • Affects ASE2000 V2 versions 2.25 to 2.37
  • CVSS score 9.8 (critical)
  • Vulnerabilities allow file read/write and outbound requests
  • Attackers can impersonate trusted peers via TLS

What happened

On August 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory concerning the Applied Systems Engineering ASE2000 V2 Communications Test Set. The advisory identifies two vulnerabilities, CVE-2018-1285 and CVE-2026-18717, affecting software versions 2.25 through 2.37. The vulnerabilities have a CVSS v3 base score of 9.8, indicating critical severity.

Successful exploitation could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.

Why it matters

The ASE2000 V2 is a communications test set used in industrial control systems. The ability to read or write arbitrary files and intercept TLS-protected communications could compromise sensitive data and system integrity. The high CVSS score underscores the urgency for organizations using affected versions to apply mitigations or updates as recommended by the vendor and CISA.

Why it matters

The ASE2000 V2 is a communications test set used in industrial environments. The critical severity and the potential for attackers to manipulate files and intercept secure communications pose significant risks to the integrity and confidentiality of data in these settings. Organizations using affected versions should review the advisory and take appropriate mitigation actions.

Sources

TMRO Report writes original coverage based on the material listed above.