Cyber Resilience
← All news
Confirmed

All-Line Equipment Company Fuel-Boss

Our takeCISA reports that Fuel-Boss V1 Standard and Portal versions tied to PHP 7.1.5 allow remote code execution via two older CVEs. Update the affected systems if you operate them.
Sources (1)
What this means for you — Security leader:CISA reports active exploitation of command-injection and PHP vulnerabilities in All-Line Equipment Fuel-Boss V1 (Standard and Portal) that allow remote arbitrary code execution. Update immediately or isolate affected units if you operate this OT fuel-management equipment.
What this means for you — Lean IT orgs:CISA reports these Fuel-Boss fuel-management systems can be remotely taken over. If you use one, check the version today and apply the vendor fix or take the unit offline.
What this means for you — MSP:CISA reports in-the-wild exploitation of command-injection and PHP flaws in All-Line Equipment Fuel-Boss V1 Standard and Portal. Scan client environments for these OT devices and patch or isolate them.
What this means for you — Researcher:CISA reports active exploitation of CVE-2018-19518 and CVE-2019-11043 in All-Line Equipment Fuel-Boss V1 Standard and Portal (<= PHP_7.1.5_7.1.5). Successful attacks enable remote arbitrary command execution.