Critical Vulnerabilities Found in Fuel-Boss Fuel Management Systems
CISA has issued a security advisory warning about vulnerabilities affecting All-Line Equipment Company's Fuel-Boss product line, including its Standard, Portal, Master/Slave, and Backflush Systems variants. The vulnerabilities stem from an outdated version of PHP (7.1.5) used within these systems, which contains known flaws that could allow attackers to inject malicious commands or trigger a buffer overflow.
If exploited, these vulnerabilities could let attackers execute arbitrary code or commands remotely on affected systems, potentially giving them significant control over fuel management operations. The issue carries a high severity rating (CVSS v3 score of 8.7), reflecting the serious risk it poses to businesses relying on this equipment, particularly those in the critical infrastructure and fuel distribution sectors.
While Fuel-Boss systems are typically used by larger fuel distribution operators, small businesses that manage fuel storage, delivery, or fleet refuelling using this equipment should take note. Running outdated software components is a common but avoidable risk, and this case highlights how legacy systems can become entry points for attackers if not properly maintained or isolated from wider networks.