THE CISA Advisory ICSA-26-239-02 discusses vulnerabilities in the All-Line Equipment Company Fuel-Boss products. The vulnerabilities, which could allow remote attackers to execute arbitrary commands, affect specific versions of Fuel-Boss. The CVEs identified are CVE-2018-19518 and CVE-2019-11043, with a CVSS score of 8.7 indicating high severity. Recommendations include applying vendor fixes for affected versions, taking non-fixed products offline, and restricting access. The advisory emphasizes minimizing network exposure and implementing cybersecurity best practices to defend against potential exploits.
Critical flaws in Fuel-Boss systems let hackers run code remotely
CyberSIXT Evidence Panel
Article by CyberSIXT