All-Line Equipment Company Fuel-Boss
CISA warns All-Line Equipment Fuel-Boss product versions contain flaws enabling remote command or code execution; fixes are available for some variants only.
CISA published ICS advisory ICSA-26-239-02 covering vulnerabilities in All-Line Equipment Company Fuel-Boss products, including the V1 Standard, V1 Portal, V1 Master/Slave, and V1 Backflush. Successful exploitation could allow attackers to execute arbitrary commands or code remotely on affected systems. Vendor fixes are available for Fuel-Boss V1 Standard and V1 Portal, fixes are not yet available for V1 Master/Slave, and no fix is planned for V1 Backflush. Customers are directed to contact All-Line Equipment Company for remediation instructions.
- Flaws allow remote execution of arbitrary commands or code on affected systems
- Fixes available for Fuel-Boss V1 Standard and V1 Portal via vendor contact
- No fix yet for V1 Master/Slave; no fix planned for V1 Backflush
- Affected versions are marked known_affected in advisory ICSA-26-239-02
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected: Fuel-Boss V1 Standard >=| =| =| =| =| =| =| =| =| =| =| =|<=PHP_7.1.5_7.1.5 Product Status: known_affected Remediations Vendor fix Fixes are available for the Fuel-Boss V1 Standard and Fuel-Boss V1 Portal. Please contact All-Line Equipment Company (866-356-3336) for instructions on how to receive these fixes. Vendor fix Fixes are not yet available for the Fuel-Boss V1 Master/Slave. Vendor fix No fix is planned for Fuel-Boss V1 Backflush…
This source does not provide full text. Read it at cisa.gov.