Our takeCISA reports active exploitation of vulnerabilities in the Applied Systems Engineering ASE2000 V2 test set that let attackers read/write arbitrary local files, issue outbound requests, or impersonate trusted peers over TLS. Update immediately if you operate these units.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:CISA reports active exploitation of vulnerabilities in the ASE2000 V2 Communications Test Set that allow arbitrary local file read/write, SSRF, and TLS impersonation. Update immediately if you operate affected versions in OT or ICS environments.
What this means for you — Lean IT orgs:If you use the ASE2000 V2 test set in your operations, check the CISA advisory and apply the vendor update right away.
What this means for you — MSP:Review client environments for any use of Applied Systems Engineering ASE2000 V2; if present, prioritize the vendor patch per the CISA advisory.
What this means for you — Researcher:CISA advisory details three vulnerabilities in ASE2000 V2 that are under active exploitation.