IM
IronMonkey Threat Research
‹ Back to ICS Advisories

All-Line Equipment Company Fuel-Boss

HIGH
CVSS 8.7
Date 2026-08-27T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2019-11043 8.7 high
Fuel-Boss running versions up to and including PHP 7.1.5 is vulnerable because certain FPM configurations allow the FPM module to write past allocated buffers into space reserved for FCGI protocol data, thereby creating a possible remote code execution condition.
CVE-2018-19518 7.5 high
Fuel-Boss is vulnerable to the University of Washington IMAP Toolkit 2007f on UNIX, used in imap_open() in PHP and other products, launching an rsh command via the imap_rimap and tcp_aopen functions without preventing argument injection, which can allow remote attackers to execute arbitrary OS commands when an untrusted IMAP server name is supplied and rsh has been replaced by a program with different argument semantics such as ssh. This enables attacks through IMAP server names containing a "-oProxyCommand" argument, as well as a stack-based buffer overflow that may allow an attacker to remotely execute arbitrary code.

// Remediations (5)

Patch: Fixes are not yet available for the Fuel-Boss V1 Master/Slave.
Fixes are not yet available for the Fuel-Boss V1 Master/Slave.
Patch: Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line E
Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line Equipment Company (866-356-3336) for instructions on how to receive these fixes.
Mitigation: All-Line Equipment Company recommends either taking products that are not fixed off the Internet or
All-Line Equipment Company recommends either taking products that are not fixed off the Internet or restricting the IP addresses that can access them at the router level.
Patch: No fix is planned for Fuel-Boss V1 Backflush Systems.
No fix is planned for Fuel-Boss V1 Backflush Systems.
Patch: Festo Didactic has released Factory Control Panel as a replacement for XAMPP on its MES PCs. Contact
Festo Didactic has released Factory Control Panel as a replacement for XAMPP on its MES PCs. Contact technical support at [email protected] to obtain the current version of Factory Control Panel which includes fixes for these vulnerabilities.

// References