Applied Systems Engineering ASE2000 V2 Communications Test Set
Summary
Applied Systems Engineering ASE2000 V2 Communications Test Set versions 2.25 through 2.37 are vulnerable to XML External Entity (XXE) injection and improper certificate validation. Successful exploitation could allow attackers to read or write local files, initiate outbound network requests, or intercept and modify communications.
IFF Assessment
These vulnerabilities allow for unauthorized file access and interception of sensitive communications, posing a significant risk to defenders.
Severity
Defender Context
This advisory highlights critical vulnerabilities in industrial control system (ICS) test equipment that are used in vital infrastructure sectors. Defenders must ensure that such equipment is patched or has mitigations applied to prevent attackers from gaining access to sensitive data or disrupting operations.