Critical Flaws Found in ASE2000 Industrial Test Tool Used in Energy and Water Sectors
CISA has issued an advisory about two vulnerabilities affecting the ASE2000 V2 Communications Test Set, a tool used in critical infrastructure sectors including energy, water, chemical, and manufacturing worldwide. The flaws, rated 9.8 out of 10 in severity, affect versions 2.25 through 2.37 of the software.
The vulnerabilities stem from improper handling of XML data and weak certificate validation. Attackers exploiting these issues could read or write files on affected systems, trigger unwanted outbound network connections, or intercept and impersonate trusted connections—potentially allowing them to eavesdrop on or tamper with supposedly secure communications.
While ASE2000 is primarily used by larger industrial operators, small businesses that supply, maintain, or interact with critical infrastructure systems should be aware that vulnerabilities like these can ripple through supply chains. Organisations using this software should consult CISA's advisory for patching guidance and apply updates as soon as they become available.