Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution in All‑Line Equipment Company Fuel‑Boss (CVE‑2018‑19518, CVE‑2019‑11043) Threatens Industrial Control Systems

CISA has flagged two high‑severity CVEs in All‑Line Equipment Company's Fuel‑Boss control‑system software that enable remote code execution. The flaws affect multiple Fuel‑Boss modules running PHP 7.1.5, putting critical manufacturing and transportation operations at risk. For SOC 2‑ready organizations, the issue underscores the need for rigorous control mapping and continuous evidence of remediation.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Remote Code Execution in All‑Line Equipment Company Fuel‑Boss (CVE‑2018‑19518, CVE‑2019‑11043) Threatens Industrial Control Systems

What It Is — The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has issued an advisory identifying two high‑severity vulnerabilities (CVE‑2018‑19518, CVE‑2019‑11043) in All‑Line Equipment Company’s Fuel‑Boss control‑system software. Both flaws allow remote attackers to inject arguments or overflow buffers, leading to arbitrary OS command execution.

Exploitability — Public proof‑of‑concept code exists for CVE‑2019‑11043; exploitation does not require authentication and can be performed over the network. CVSS v3.1 base score: 8.7 (High).

Affected Products — Fuel‑Boss V1 Standard, Portal, Master/Slave, and Backflush Systems running PHP 7.1.5 (or earlier) are vulnerable.

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The vulnerabilities expose gaps in your application‑security and change‑management controls; mapping these to SOC 2 Trust Services Criteria (CC6, CC7) demonstrates due diligence.
  • Continuous Evidence – Automated evidence of patch status and configuration baselines satisfies the “monitoring” and “risk mitigation” requirements auditors look for.
  • Enterprise Buyer Expectations – Critical‑infrastructure customers now demand proof that vendors maintain a documented, auditable remediation process for known software flaws.

Recommended Actions

  • Identify all Fuel‑Boss instances and verify PHP version.
  • Patch to a version beyond PHP 7.1.5 or apply vendor‑provided mitigations immediately.
  • Update your control inventory: map the RCE risk to SOC 2 CC6 (System Operations) and CC7 (Change Management).
  • Capture patch‑deployment logs as immutable audit evidence.
  • Integrate continuous monitoring to alert on future vulnerable component detections.

Source: CISA Advisory – ICSA‑26‑239‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-02 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →