ASE2000 versions 2.35 through 2.37 contain an improper certificate validation vulnerability affecting TLS communications. The flaw allows an attacker to impersonate a trusted peer and successfully complete a TLS handshake without proper certificate verification. Once the handshake is completed, the attacker can intercept, read, or modify protected communications. This is a classic man-in-the-middle (MitM) attack vector enabled by weak certificate handling. The vulnerability has been reported via CISA ICS Advisory ICSA-26-239-04, indicating it affects operational technology (OT) environments. ASE Systems is the vendor of the affected product. Users running affected versions should apply patches or mitigations as recommended by the vendor and CISA.