VYPR
advisoryPublished Aug 27, 2026· 1 source

CISA Warns of Critical Vulnerabilities in All-Line Equipment Company Fuel-Boss Systems

CISA has issued an advisory detailing multiple critical vulnerabilities in All-Line Equipment Company's Fuel-Boss systems, potentially allowing remote attackers to execute arbitrary commands.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding several severe vulnerabilities affecting All-Line Equipment Company's Fuel-Boss industrial control systems. These flaws, impacting versions running PHP 7.1.5 or earlier, could permit remote attackers to execute arbitrary commands or code on compromised systems, posing a significant risk to critical infrastructure sectors.

The vulnerabilities identified are CVE-2018-19518 and CVE-2019-11043. CVE-2018-19518 stems from an argument injection flaw within the University of Washington IMAP Toolkit 2007f, which is used in PHP's imap_open() function. This flaw, when combined with specific configurations, can allow attackers to inject malicious commands into IMAP server names, leading to remote code execution. A related stack-based buffer overflow vulnerability further exacerbates this risk.

CVE-2019-11043 is a buffer overflow vulnerability specifically affecting PHP FPM configurations. In certain setups, the FPM module can write beyond allocated buffer boundaries into space designated for FCGI protocol data. This overflow condition can be exploited by remote attackers to achieve arbitrary code execution on the affected Fuel-Boss systems.

Multiple versions of the Fuel-Boss system are susceptible to these vulnerabilities, including Fuel-Boss V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush Systems, provided they are running PHP versions 7.1.5 or earlier. The affected systems are deployed across critical infrastructure sectors such as Critical Manufacturing, Defense Industrial Base, Emergency Services, and Transportation Systems, with a global reach.

Remediation efforts are underway, but the availability of fixes varies by product. All-Line Equipment Company has provided fixes for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal, and customers are advised to contact the company directly for instructions. However, no fixes are currently available for the Fuel-Boss V1 Master/Slave, and no remediation is planned for the Fuel-Boss V1 Backflush Systems, leaving these versions particularly vulnerable.

In response to the lack of immediate fixes for some systems, All-Line Equipment Company recommends significant mitigation strategies. Organizations are urged to either disconnect vulnerable systems from the internet entirely or implement strict IP address restrictions at the router level to limit external access. This is crucial for preventing potential exploitation.

CISA strongly advises users to implement defensive measures to minimize the risk of exploitation. This includes minimizing network exposure of all control system devices, ensuring they are not accessible from the internet, and isolating them behind firewalls. When remote access is necessary, more secure methods like VPNs should be employed, with the caveat that VPNs themselves must be kept up-to-date.

The agency emphasizes the importance of performing thorough impact analysis and risk assessments before deploying any defensive measures. CISA also directs organizations to its ICS cybersecurity best practices and resources, such as "Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies," to bolster their defenses against such threats.

Synthesized by Vypr AI