security1 distinct publisher
ASE2000's IEC 104 client accepts a forged peer certificate through version 2.37
Two flaws in Applied Systems Engineering's ASE2000 V2 test set, one of them an eight-year-old log4net XXE, let an attacker read local files and sit inside the TLS session engineers use to check SCADA traffic. Version 2.38 fixes both.
Publishers:cisa.gov
Reality
- Evidence68
- Adoption30
- Hype gap−8
- Incentives42