Junglewise Threat Intelligence

CVE-2024-9537: ScienceLogic SL1 Unspecified Vulnerability

CVE-2024-9537 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-10-21

Executive brief

ScienceLogic SL1 (formerly EM7) contains an unspecified vulnerability within a third-party component packaged with the software. The flaw allows for remote exploitation and has been observed in the wild, notably linked to a breach at Rackspace.

Affected products

  • ScienceLogic SL1 10.1.x, 10.2.x, 11.1.x, 11.2.x, 11.3.x, 12.1.x < 12.1.3, 12.2.x < 12.2.3, 12.3.x < 12.3.0

Timeline

  • 2024-09-30: disclosed: Public reports of zero-day exploitation linked to Rackspace breach.
  • 2024-10-21: advisory: CVE-2024-9537 published and added to CISA KEV catalog.
  • 2024-10-21: kev added