What happened
On August 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory concerning the Applied Systems Engineering ASE2000 V2 Communications Test Set. The advisory identifies two vulnerabilities, CVE-2018-1285 and CVE-2026-18717, affecting software versions 2.25 through 2.37. The vulnerabilities have a CVSS v3 base score of 9.8, indicating critical severity.
Successful exploitation could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
Why it matters
The ASE2000 V2 is a communications test set used in industrial control systems. The ability to read or write arbitrary files and intercept TLS-protected communications could compromise sensitive data and system integrity. The high CVSS score underscores the urgency for organizations using affected versions to apply mitigations or updates as recommended by the vendor and CISA.