highOther

All-Line Equipment Company Fuel-Boss Argument Injection and Buffer Overflow Vulnerabilities

First seen Aug 29, 2026 · Updated Aug 29, 2026 · CVSS 8.7

icsotcisa-advisoryfuel-managementargument-injectionbuffer-overflowrcephplegacy-software

All-Line Equipment Company's Fuel-Boss fuel management systems (Standard, Portal, Master/Slave, and Backflush variants) running PHP 7.1.5 or earlier are vulnerable to two high-severity flaws: an argument injection vulnerability in the PHP imap_open() function and a buffer overflow in PHP-FPM's FastCGI handling. Successful exploitation could allow remote attackers to execute arbitrary OS commands or code on affected systems, posing risk to critical manufacturing, defense, emergency services, and transportation sector operators using this equipment.

Technical Analysis

CVE-2018-19518 stems from the University of Washington IMAP Toolkit's imap_rimap and tcp_aopen functions, used by PHP's imap_open(), failing to sanitize IMAP server name arguments, enabling argument injection (e.g., via a crafted '-oProxyCommand' string) and a stack-based buffer overflow that can lead to remote code execution (CVSS 3.1: 7.5 High). CVE-2019-11043 is a buffer overflow in PHP-FPM under specific Nginx/FPM configurations, allowing writes past allocated buffers into FCGI protocol space, resulting in remote code execution (CVSS 3.1: 8.7 High, CVSS 4.0: 9.4 Critical). Both flaws affect legacy PHP 7.1.5 runtime embedded in Fuel-Boss V1 product lines; exploitation complexity is high but impact on confidentiality, integrity, and availability is severe. These are OT/ICS-focused vulnerabilities in fuel dispensing and backflush control systems with no known direct AI agent integration, so agent-system impact is not applicable here.

Affected Systems

All-Line Equipment Company Fuel-Boss V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush Systems running PHP version 7.1.5 or earlier (PHP_7.1.5_7.1.5 range).

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided; this is a vulnerability disclosure, not an active exploitation campaign report.

Remediation Steps

  1. 1

    Apply vendor fixes

    Contact All-Line Equipment Company (866-356-3336) to obtain available fixes for Fuel-Boss V1 Standard and V1 Portal products.

  2. 2

    Monitor for Master/Slave fix availability

    No fix is currently available for Fuel-Boss V1 Master/Slave; monitor vendor communications for future patches.

  3. 3

    Plan for Backflush Systems end-of-life

    No fix is planned for Fuel-Boss V1 Backflush Systems; consider replacement or additional compensating controls.

  4. 4

    Restrict network exposure

    Remove unpatched devices from direct internet access and restrict access via router-level IP allowlisting.

  5. 5

    Network segmentation

    Place control system networks and devices behind firewalls and isolate them from business/IT networks.

  6. 6

    Secure remote access

    Use VPNs with up-to-date patching for any required remote access, recognizing VPN security depends on connected endpoint security.

  7. 7

    Report suspicious activity

    Follow internal incident response procedures and report suspected malicious activity to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2018-19518CVE-2019-11043

Industries Most Exposed

Critical ManufacturingDefense Industrial BaseEmergency ServicesTransportation Systems

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.