CVE-2026-90647: CWE-295 Improper Certificate Validation in Kalkitech ASE2000 V2 Communication Test Set
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
AI Analysis
Technical Summary
CVE-2026-90647 is a critical vulnerability in Kalkitech ASE2000 V2 Communication Test Set (versions 2.35 to 2.37) affecting the IEC 60870-5-104 TLS client in Task Mode. The vulnerability arises from improper certificate validation (CWE-295), which allows a network attacker to bypass TLS certificate checks by presenting a certificate containing multiple faults simultaneously. This bypass enables the attacker to intercept and potentially manipulate protected communications via a MitM attack.
Potential Impact
An attacker positioned on the network can exploit this vulnerability to bypass TLS certificate validation, compromising the confidentiality and integrity of communications between the client and server. This enables Man-in-the-Middle attacks that can intercept, modify, or inject data into the protected communication channel.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider restricting network access to trusted entities and monitoring for suspicious network activity related to the affected product.
CVE-2026-90647: CWE-295 Improper Certificate Validation in Kalkitech ASE2000 V2 Communication Test Set
Description
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
CVSS v4.0
Score 9.1critical
Affected software
Kalkitech
ASE2000 V2 Communication Test Set
pkg:github/kalkitech/ase2000-v2-communication-test-setRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-90647 is a critical vulnerability in Kalkitech ASE2000 V2 Communication Test Set (versions 2.35 to 2.37) affecting the IEC 60870-5-104 TLS client in Task Mode. The vulnerability arises from improper certificate validation (CWE-295), which allows a network attacker to bypass TLS certificate checks by presenting a certificate containing multiple faults simultaneously. This bypass enables the attacker to intercept and potentially manipulate protected communications via a MitM attack.
Potential Impact
An attacker positioned on the network can exploit this vulnerability to bypass TLS certificate validation, compromising the confidentiality and integrity of communications between the client and server. This enables Man-in-the-Middle attacks that can intercept, modify, or inject data into the protected communication channel.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider restricting network access to trusted entities and monitoring for suspicious network activity related to the affected product.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-09-12T22:28:32.772Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa5d66655bf5e2cf5d5649a
Added to database: 09/12/2026, 22:47:02 UTC
Last enriched: 09/12/2026, 23:01:27 UTC
Last updated: 09/13/2026, 03:10:16 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.