安装于 Windows 平台、版本为 2.35 至 2.37 的 ASE/Kalkitech ASE2000 V2 通信测试仪,在其 IEC 60870-5-104 协议的任务模式(Task Mode)TLS 客户端中存在证书验证不当的漏洞。 由于该漏洞,处于网络中间位置的攻击者可以通过使用一个存在多重并发缺陷的证书,绕过系统的证书验证机制,从而对受保护的通信链路发起中间人(MitM)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kalkitech | ASE2000 V2 Communication Test Set | 2.35 ~ 2.38 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet