CISA published an ICS advisory detailing two remote code execution vulnerabilities in All-Line Equipment Company Fuel-Boss V1 products running PHP 7.1.5 or earlier. CVE-2018-19518 exploits argument injection in PHP's imap_open() function to execute arbitrary OS commands. CVE-2019-11043 exploits a buffer overflow in PHP-FPM configurations to achieve remote code execution. Fixes are available for two of four product variants; the remaining two have no fix or no planned fix.
PHP RCE
1 post
All-Line Equipment Company Fuel-Boss (CVE-2018-19518, CVE-2019-11043)