Our takeCISA reports that Fuel-Boss V1 Standard and Portal versions tied to PHP 7.1.5 allow remote code execution via two older CVEs. Update the affected systems if you operate them.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:CISA reports that Fuel-Boss V1 Standard and Portal versions tied to PHP 7.1.5 allow remote code execution via CVE-2018-19518 and CVE-2019-11043. Update or isolate affected systems immediately.
What this means for you — Lean IT orgs:If you run Fuel-Boss for fuel inventory, check the version tied to PHP 7.1.5. Update the software or take the system offline until you can.
What this means for you — MSP:Scan client environments for All-Line Equipment Fuel-Boss V1 Standard or Portal running on PHP 7.1.5. Patch or segment any instances found.
What this means for you — Researcher:CISA advisory ICSA-26-239-02 details remote code execution in All-Line Equipment Fuel-Boss V1 (Standard and Portal) via CVE-2018-19518 and CVE-2019-11043.