Improper Certificate Validation in ASE/Kalkitech ASE2000 V2 Communication Test Set on Windows
CVE-2026-90647
9.1CRITICAL
Key Information:
- Vendor
Kalkitech
- Vendor
- CVE Published:
- 12 September 2026
What is CVE-2026-90647?
The ASE/Kalkitech ASE2000 V2 Communication Test Set, versions 2.35 through 2.37, for Windows is susceptible to an improper certificate validation vulnerability. This flaw arises within the IEC 60870-5-104 TLS client (Task Mode), permitting an attacker with network access to execute a Man-in-the-Middle attack. The attacker can exploit this weakness by using a certificate that possesses multiple simultaneous faults, thereby bypassing essential certificate validation mechanisms and compromising secure communications.
Affected Version(s)
ASE2000 V2 Communication Test Set Windows 2.35 < 2.38
