CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

All-Line Equipment Company Fuel-Boss

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5269

As cited

Copy frozen at (site build).

vulnerabilities

All-Line Equipment Company Fuel-Boss

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

All-Line Equipment Company Fuel-Boss

All-Line Equipment Company Fuel-Boss V1 versions running PHP 7.1.5 contain two critical vulnerabilities: CVE-2018-19518 (argument injection and buffer overflow in IMAP handling) and CVE-2019-11043 (buffer overflow in FPM configuration), both allowing remote code execution. Fixes are available for Standard and Portal versions; Master/Slave versions have no fix date, and Backflush Systems versions will not be patched. All-Line Equipment Company recommends taking unfixed systems offline or restricting network access at the router level.

Why it matters: Organizations operating Fuel-Boss systems in critical manufacturing, defense, emergency services, and transportation sectors must immediately identify affected versions and apply patches where available or implement network isolation to prevent remote code execution exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

All-Line Equipment Company Fuel-Boss

All-Line Equipment Company Fuel-Boss V1 versions running PHP 7.1.5 contain two critical vulnerabilities: CVE-2018-19518 (argument injection and buffer overflow in IMAP handling) and CVE-2019-11043 (buffer overflow in FPM configuration), both allowing remote code execution. Fixes are available for Standard and Portal versions; Master/Slave versions have no fix date, and Backflush Systems versions will not be patched. All-Line Equipment Company recommends taking unfixed systems offline or restricting network access at the router level.

Why it matters: Organizations operating Fuel-Boss systems in critical manufacturing, defense, emergency services, and transportation sectors must immediately identify affected versions and apply patches where available or implement network isolation to prevent remote code execution exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary