No fix planned for Fuel-Boss Backflush Systems RCE
Backflush variant operators get only network isolation against two remotely exploitable RCE flaws rated up to CVSS 9.4, with no vendor patch on the roadmap.
TL;DR
CISA published an ICS advisory for two remote code execution vulnerabilities (CVE-2018-19518, CVE-2019-11043) affecting all four variants of All-Line Equipment's Fuel-Boss V1 fuel management system, deployed worldwide across critical manufacturing, defense industrial base, emergency services, and transportation sectors. Standard and Portal variants have vendor fixes available by phone. Master/Slave fixes are pending. Backflush Systems operators get no planned patch, only a recommendation to air-gap or restrict IP access at the router.
The advisory covers two vulnerabilities that originate in PHP itself, CVE-2018-19518, an IMAP argument injection in PHP's imap_open() that can chain into remote OS command execution, and CVE-2019-11043, a buffer overflow in PHP-FPM that creates a remote code execution path. Both were publicly disclosed years ago. Their appearance in Fuel-Boss suggests the product runs an embedded PHP stack that hasn't been updated since at least 2019.
The remediation picture splits three ways. Fuel-Boss V1 Standard and Portal operators can get fixes by calling All-Line Equipment directly, no download portal, no advisory page, just a phone number. Master/Slave fixes are forthcoming, with no timeline. And Backflush Systems gets nothing: the vendor states plainly that no fix is planned. For a product deployed in critical infrastructure sectors with a vulnerability scored at CVSS 9.4, that's a striking remediation posture. CISA's own recommended mitigations (network isolation behind firewalls with VPN-restricted access where remote connectivity is unavoidable) are what Backflush operators are left holding.
For the practitioner, the immediate task is inventory: if Fuel-Boss V1 runs anywhere in your OT environment, identify which variant and segment it aggressively. If it's Backflush Systems, treat it as unpatchable and isolate accordingly. The phone number for Standard and Portal fixes is 866-356-3336, document the call, because there's no public patch changelog to reference.
Published ·Deep Fathom