← Back to Feed

All-Line Equipment Company Fuel-Boss

CVE-2018-19518CVE-2019-11043

August 27, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected: Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Master/Slave >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Backflush Systems >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) CVSS Vendor Equipment Vulnerabilities v3 8.7 All-Line Equipment Company All-Line Equipment Company Fuel-Boss Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Background Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Emergency Services, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2018-19518 Fuel-Boss is vulnerable to the University of Washington IMAP Toolkit 2007f on UNIX, used in imap_open() in PHP and other products, launching an rsh command via the imap_rimap and tcp_aopen functions without preventing argument injection, which can allow remote attackers to execute arbitrary OS commands when an untrusted IMAP server name is supplied and rsh has been replaced by a program with different argument semantics such as ssh. This enables attacks through IMAP server names containing a "-oProxyCommand" argument, as well as a stack-based buffer overflow that may allow an attacker to remotely execute arbitrary code. View CVE Details Affected Products All-Line Equipment Company Fuel-Boss Vendor:All-Line Equipment Company Product Version:All-Line Equipment Company Fuel-Boss V1 Standard: >=|<=PHP_7.1.5_7.1.5, All-Line Equipment Company Fuel-Boss V1 Portal:...

Key Takeaways

  • CISA published an advisory for All-Line Equipment Company Fuel-Boss urging users to apply vendor patches and mitigations.
  • The advisory covers 1 vulnerabilities in All-Line Equipment Company Fuel-Boss that require immediate patching.
  • Active exploitation of vulnerabilities in All-Line Equipment Company Fuel-Boss has been reported, making patching urgent for affected organizations.
☕ Buy a Coffee