SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-90647

HIGH · CVSS 7.4

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The ASE2000 V2 Communication Test Set versions 2.35 through 2.37 on Windows is vulnerable due to improper certificate validation in its IEC 60870-5-104 TLS client, which can be exploited by attackers to perform Man-in-the-Middle attacks. This vulnerability allows malicious actors to bypass certificate validation using a compromised certificate, potentially compromising sensitive communications. Organizations utilizing this software, particularly in critical infrastructure and industrial control systems, should prioritize immediate remediation to mitigate the risk of unauthorized access and data interception.

CVE
CVE-2026-90647
Severity
HIGH
CVSS
7.4
EPSS
N/A
Windows

Original NVD Description

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.