[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-90647":6},{"stargazers_count":4,"fetched_at":5},7,"2026-09-14T00:59:52.343Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":28,"duplicate_of":9,"upstream":29,"downstream":30,"duplicates":31,"related":32,"reserved_at":9,"published_at":33,"modified_at":33,"state":34,"summary":35,"references_raw":42,"kevs":49,"epss":9,"epss_history":50,"metrics":51,"affected":65},"CVE-2026-90647","ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-295","Improper Certificate Validation","The product does not validate, or incorrectly validates, a certificate.","weakness","Draft","Base",[19,23],{"id":20,"name":21,"techniques":22},"CAPEC-459","Creating a Rogue Certification Authority Certificate",[],{"id":24,"name":25,"techniques":26},"CAPEC-475","Signature Spoofing by Improper Validation",[],[],[],[],[],[],[],"2026-09-12T22:38:16.637Z","Received",{"cisa_kev":36,"cisa_ransomware":36,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":37,"severity_score":38,"severity_version":39,"severity_source":40,"severity_vector":41,"severity_status":34},false,"critical",9.1,"v4.0","cve.org","CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",[43],{"url":44,"sources":45,"tags":47},"https://www.ase-systems.com/wp-content/uploads/2026/07/CYB_2026_86278_Advisory_v1.0.pdf",[40,46],"nvd",[48],"Vendor Advisory",[],[],[52,61],{"source":40,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":53,"cvss_v4_0":59},{"baseScore":54,"baseSeverity":55,"vectorString":56,"impactScore":57,"exploitabilityScore":58},7.4,"HIGH","CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",8.7,5.6,{"baseScore":38,"baseSeverity":60,"vectorString":41,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":46,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":62,"cvss_v4_0":63},{"baseScore":54,"baseSeverity":55,"vectorString":56,"impactScore":57,"exploitabilityScore":58},{"baseScore":38,"baseSeverity":60,"vectorString":64,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[66],{"ecosystem":9,"name":67,"vendor":68,"product":69,"cpe_part":70,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":71},"ASE2000 V2 Communication Test Set","kalkitech","ase2000 v2 communication test set","a",[72],{"version":73,"is_range":74,"range_type":40,"version_start":75,"version_start_type":76,"version_end":77,"version_end_type":78,"fixed_in":9},">= 2.35, \u003C 2.38",true,"2.35","including","2.38","excluding"]