PatchSiren

Kalkitech CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Kalkitech CVE published 2026-09-12

CVE-2026-90647

A critical vulnerability exists in ASE/Kalkitech ASE2000 V2 Communication Test Set versions 2.35 through 2.37 on Windows. The IEC 60870-5-104 TLS client (Task Mode) improperly validates certificates, allowing a network-positioned attacker to bypass validation using a faulty certificate. This enables a Man-in-the-Middle attack on protected communications.