CVE-2026-90647
Received Received - Intake

Improper Certificate Validation in ASE/Kalkitech ASE2000 V2 Communication Test Set

Vulnerability report for CVE-2026-90647, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: MITRE

Description

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-13
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kalkitech ase2000 From 2.35 (inc) to 2.37 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows has an improper certificate validation flaw in its IEC 60870-5-104 TLS client. This allows attackers in a network position to bypass certificate checks using a certificate with multiple faults, enabling Man-in-the-Middle attacks on protected communications.

Detection Guidance

Detecting this vulnerability requires checking for improper certificate validation in the ASE/Kalkitech ASE2000 V2 Communication Test Set. Inspect TLS client configurations and certificates used by the IEC 60870-5-104 protocol. Monitor network traffic for anomalies or unexpected certificate chains.

Impact Analysis

This vulnerability could allow attackers to intercept, modify, or eavesdrop on communications between the ASE2000 device and other systems. It may lead to unauthorized access to sensitive data or manipulation of commands, potentially disrupting operations in industrial or utility environments.

Compliance Impact

This vulnerability could violate compliance requirements that mandate secure communications, such as GDPR's data protection principles or HIPAA's safeguards for protected health information. Failure to address it may result in non-compliance penalties and increased risk of data breaches.

Mitigation Strategies

Update the ASE2000 software to the latest version. Ensure strict certificate validation is enforced in the IEC 60870-5-104 TLS client settings. Disable the device if updates are unavailable or isolate it from critical networks until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90647. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart