{"id":"CVE-2026-90647","title":"ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode)","summary":"ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass cer…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-295"],"vendor":"Kalkitech","product":"ASE2000 V2 Communication Test Set","affected":["ase2000_v2_communication_test_set >= 2.35 < 2.38"],"published":"2026-09-12","updated":"2026-09-15","sourceUpdated":"2026-09-15T18:19:37.743","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90647","references":[{"url":"https://www.ase-systems.com/wp-content/uploads/2026/07/CYB_2026_86278_Advisory_v1.0.pdf","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00137,"epssPercentile":0.03466,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-15T17:09:34.244525Z"},"ingestedAt":"2026-09-14T15:23:07.477Z","slug":"CVE-2026-90647","body":"## Overview\n\nASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}