Security & Threat Intelligence · 27.08.2026, 15:48 UTC
All-Line Equipment Company Fuel-Boss
| Schweregrad | high aktiv ausgenutzt (KEV) |
|---|---|
| CVE | ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 27.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2018-19518, CVE-2019-11043. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected:
Fuel-Boss V1 Standard >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Portal >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Master/Slave >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043) Fuel-Boss V1 Backflush Systems >=|<=PHP_7.1.5_7.1.5 (CVE-2018-19518, CVE-2019-11043)
CVSS Vendor Equipment Vulnerabilities
v3 8.7 All-Line Equipment Company All-Line Equipment Company Fuel-Boss Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Emergency Services, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2018-19518
Fuel-Boss is vulnerable to the University of Washington IMAP Toolkit 2007f on UNIX, used in imap_open() in PHP and other products, launching an rsh command via the imap_rimap and tcp_aopen functions without preventing argument injection, which can allow remote attackers to execute arbitrary OS commands when an untrusted IMAP server name is supplied and rsh has been replaced by a program with different argument semantics such as ssh. This enables attacks through IMAP server names containing a "-oProxyCommand" …