All-Line Equipment Company Fuel-Boss
Summary
Multiple vulnerabilities have been identified in All-Line Equipment Company's Fuel-Boss systems, specifically affecting versions running PHP 7.1.5 or earlier. Successful exploitation could allow remote attackers to execute arbitrary commands or code on affected industrial control systems.
IFF Assessment
The identified vulnerabilities in industrial control systems allow for remote code execution, posing a significant threat to critical infrastructure.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: April 15, 2022. Known ransomware use: Known.
Defender Context
Defenders monitoring critical infrastructure should be aware of these vulnerabilities affecting All-Line Equipment Company Fuel-Boss systems. The combination of argument injection and buffer overflow flaws presents a severe risk, demanding immediate patching or mitigation strategies for affected OT environments.