CRITICAL
Kalkitech
CVE published 2026-09-12
CVE-2026-90647
A critical vulnerability exists in ASE/Kalkitech ASE2000 V2 Communication Test Set versions 2.35 through 2.37 on Windows. The IEC 60870-5-104 TLS client (Task Mode) improperly validates certificates, allowing a network-positioned attacker to bypass validation using a faulty certificate. This enables a Man-in-the-Middle attack on protected communications.