External risk intelligence

ASE/Kalkitech IEC 60870-5-104 TLS Client Improper Certificate Validation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-90647

The vulnerability affects a communication test set tool used for industrial protocol testing (IEC 60870-5-104). Such tools are typically operated within internal engineering, testing, or industrial control network environments rather than being exposed to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in communication testing software could allow a network attacker to intercept protected communications by bypassing certificate validation. This could lead to a Man-in-the-Middle attack on sensitive industrial data.

  • Bypass security checks to intercept communications.
  • Understand potential impact on industrial control systems.
  • Confirm relevance and exposure within your environment.

Attack Path

How an attacker could exploit the issue

An attacker with network access could target the IEC 60870-5-104 TLS client within the communication test set. By presenting a certificate with multiple faults, the attacker can trick the client into bypassing validation, enabling them to intercept and tamper with communications. This could lead to a Man-in-the-Middle attack on protected data exchanges.

  • Network access required.
  • Bypasses certificate validation.
  • Enables Man-in-the-Middle attacks.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a Man-in-the-Middle attack could impact communications protected by the IEC 60870-5-104 TLS client, potentially affecting the integrity and confidentiality of data exchanged during testing or operational scenarios.

  • Protected communication data
  • Man-in-the-Middle attack bypass
  • Compromised test integrity

Operational Fix

Recommended remediation, mitigation, and detection steps

The ASE/Kalkitech ASE2000 V2 Communication Test Set is affected by an improper certificate validation vulnerability. This could allow a network attacker to conduct a Man-in-the-Middle attack, bypassing certificate validation on protected communications. Action owners should first identify all instances of the affected tool, assess their network exposure and criticality, and then coordinate with the vendor for remediation.

  • Ownership likely rests with industrial control system or network security teams.
  • Verify tool reachability and business criticality first.
  • Coordinate vendor remediation and plan for risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ASE/Kalkitech ASE2000 V2 Communication Test Set?

This software is a specialized tool used by engineers to test and analyze industrial communication protocols. It specifically supports the IEC 60870-5-104 standard, which is widely utilized for telecontrol and monitoring in power systems and infrastructure. Technicians use it to verify data exchanges between devices, making it a critical component for validating the reliability of industrial control network communications.

What does CVE-2026-90647 mean by improper certificate validation?

This vulnerability, classified as CWE-295, occurs when software fails to correctly verify the authenticity of a digital certificate. In this instance, the IEC 60870-5-104 TLS client can be misled by a malicious certificate that contains multiple simultaneous faults. Instead of rejecting the untrusted connection, the software incorrectly accepts it, allowing an attacker to bypass standard security checks.

How does an attacker trigger this vulnerability?

An attacker must be positioned on the network between the test set and the communication partner to intercept traffic. They trigger the flaw by presenting a specifically crafted certificate containing multiple errors to the software. It is important to note that this requires active network intervention; simply being on the same network is not enough, as the attacker must successfully perform the Man-in-the-Middle intercept during the TLS handshake.

Why should I care about this vulnerability in my network?

The risk depends on how your software is deployed. According to Halo Surface Signal, this tool is generally used within internal engineering or industrial control networks rather than public-facing environments. You should care if your instances are accessible from network segments that are not fully trusted, as a compromise could allow an attacker to intercept or modify sensitive industrial data flows during testing.

How do I respond to the CVE-2026-90647 advisory?

Begin by creating an inventory of all systems running the ASE2000 V2 software in your environment. Once identified, evaluate the network accessibility and business criticality of each instance. Because this is a vendor-supplied software flaw, you should prioritize checking the manufacturer's official resources for updates or configuration guidance while limiting the tool's exposure to untrusted network segments.

References