Our takeCISA published an ICS advisory on Applied Systems Engineering ASE2000 V2 Communications Test Set flaws that can allow arbitrary local file read/write, outbound requests, or TLS interception. Update if you operate the affected versions.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation of vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set that let attackers read or write arbitrary local files, issue outbound requests, or perform TLS impersonation and modify protected communications. Update immediately if you operate affected versions in OT or ICS environments.
What this means for you — Lean IT orgs:If you use the ASE2000 V2 test set in your operations, check the CISA advisory and apply the vendor update as soon as possible. Most lean teams can treat this as vendor-managed equipment and simply ask their supplier if it is patched.
What this means for you — MSP:Review client environments for any use of Applied Systems Engineering ASE2000 V2 test sets and ensure the vendor update is applied. Prioritize OT/ICS clients that rely on it for communications testing.
What this means for you — Researcher:CISA reports active exploitation of arbitrary file read/write, SSRF, and TLS impersonation vulnerabilities in the Applied Systems Engineering ASE2000 V2 Communications Test Set. See the CSAF for full technical details.