Apply vendor-provided fixes for Fuel-Boss V1 Standard and Portal models. For Master/Slave and Backflush Systems, where fixes are unavailable or not planned, take systems offline or restrict IP access at the router level. Monitor vendor communications for future updates.
Quick answers
What is CVE-2018-19518?
Apply vendor-provided fixes for Fuel-Boss V1 Standard and Portal models. For Master/Slave and Backflush Systems, where fixes are unavailable or not planned, take systems offline or restrict IP access at the router level. Monitor vendor communications for future updates.
How severe is CVE-2018-19518?
high, CVSS 8.7
Is CVE-2018-19518 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2018-19518 be mitigated?
Apply vendor-provided fixes for Fuel-Boss V1 Standard and Portal models. For Master/Slave and Backflush Systems, where fixes are unavailable or not planned, take systems offline or restrict IP access at the router level. Monitor vendor communications for future updates.
Apply vendor-provided fixes for Fuel-Boss V1 Standard and Portal models. For Master/Slave and Backflush Systems, where fixes are unavailable or not planned, take systems offline or restrict IP access at the router level. Monitor vendor communications for future updates.
CISA has published an advisory (ICSA-26-239-02) detailing two high-severity vulnerabilities in All-Line Equipment Company's Fuel-Boss V1 systems. The flaws, identified as CVE-2018-19518 and CVE-2019-11043, could allow remote attackers to execute arbitrary commands or code on affected devices. Exploitation could disrupt fuel management operations in critical infrastructure sectors, including manufacturing, defense, emergency services, and transportation. Patches are available for some models, but others remain unfixed or have no planned remediation.