Cyber Resilience
← All news
Confirmed

All-Line Equipment Company Fuel-Boss

Our takeCISA reports that Fuel-Boss V1 Standard and Portal versions tied to PHP 7.1.5 allow remote code execution via two older CVEs. Update the affected systems if you operate them.
Sources (1)
What this means for you — Security leader:CISA reports that Fuel-Boss V1 Standard and Portal versions tied to PHP 7.1.5 allow remote code execution via CVE-2018-19518 and CVE-2019-11043. Update or isolate affected systems immediately.
What this means for you — Lean IT orgs:If you run Fuel-Boss for fuel inventory, check the version tied to PHP 7.1.5. Update the software or take the system offline until you can.
What this means for you — MSP:Scan client environments for All-Line Equipment Fuel-Boss V1 Standard or Portal running on PHP 7.1.5. Patch or segment any instances found.
What this means for you — Researcher:CISA advisory ICSA-26-239-02 details remote code execution in All-Line Equipment Fuel-Boss V1 (Standard and Portal) via CVE-2018-19518 and CVE-2019-11043.