Our takeCISA reports that Fuel-Boss V1 Standard and Portal versions tied to PHP 7.1.5 allow remote code execution via two older CVEs. Update the affected systems if you operate them.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation of command-injection and PHP vulnerabilities in All-Line Equipment Fuel-Boss V1 (Standard and Portal) that allow remote arbitrary code execution. Update immediately or isolate affected units if you operate this OT fuel-management equipment.
What this means for you — Lean IT orgs:CISA reports these Fuel-Boss fuel-management systems can be remotely taken over. If you use one, check the version today and apply the vendor fix or take the unit offline.
What this means for you — MSP:CISA reports in-the-wild exploitation of command-injection and PHP flaws in All-Line Equipment Fuel-Boss V1 Standard and Portal. Scan client environments for these OT devices and patch or isolate them.
What this means for you — Researcher:CISA reports active exploitation of CVE-2018-19518 and CVE-2019-11043 in All-Line Equipment Fuel-Boss V1 Standard and Portal (<= PHP_7.1.5_7.1.5). Successful attacks enable remote arbitrary command execution.