Applied Systems Engineering ASE2000 V2 Communications Test Set

Summary

Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37 are vulnerable to XML External Entity (XXE) injection and improper certificate validation. Successful exploitation could allow attackers to read or write local files, initiate outbound network requests, or intercept and modify communications.

IFF Assessment

FOE

These vulnerabilities allow for unauthorized file access and interception of sensitive communications, posing a significant risk to defenders.

Severity

9.8 Critical

Defender Context

This advisory highlights critical vulnerabilities in industrial control system (ICS) test equipment that are used in vital infrastructure sectors. Defenders must ensure that such equipment is patched or has mitigations applied to prevent attackers from gaining access to sensitive data or disrupting operations.

Read Full Story →