Remote Code Execution in All‑Line Equipment Company Fuel‑Boss (CVE‑2018‑19518, CVE‑2019‑11043) Threatens Industrial Control Systems
What It Is — The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has issued an advisory identifying two high‑severity vulnerabilities (CVE‑2018‑19518, CVE‑2019‑11043) in All‑Line Equipment Company’s Fuel‑Boss control‑system software. Both flaws allow remote attackers to inject arguments or overflow buffers, leading to arbitrary OS command execution.
Exploitability — Public proof‑of‑concept code exists for CVE‑2019‑11043; exploitation does not require authentication and can be performed over the network. CVSS v3.1 base score: 8.7 (High).
Affected Products — Fuel‑Boss V1 Standard, Portal, Master/Slave, and Backflush Systems running PHP 7.1.5 (or earlier) are vulnerable.
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The vulnerabilities expose gaps in your application‑security and change‑management controls; mapping these to SOC 2 Trust Services Criteria (CC6, CC7) demonstrates due diligence.
- Continuous Evidence – Automated evidence of patch status and configuration baselines satisfies the “monitoring” and “risk mitigation” requirements auditors look for.
- Enterprise Buyer Expectations – Critical‑infrastructure customers now demand proof that vendors maintain a documented, auditable remediation process for known software flaws.
Recommended Actions
- Identify all Fuel‑Boss instances and verify PHP version.
- Patch to a version beyond PHP 7.1.5 or apply vendor‑provided mitigations immediately.
- Update your control inventory: map the RCE risk to SOC 2 CC6 (System Operations) and CC7 (Change Management).
- Capture patch‑deployment logs as immutable audit evidence.
- Integrate continuous monitoring to alert on future vulnerable component detections.
Source: CISA Advisory – ICSA‑26‑239‑02