Executive brief
ScienceLogic SL1 (formerly EM7) contains an unspecified vulnerability within a third-party component packaged with the software. The flaw allows for remote exploitation and has been observed in the wild, notably linked to a breach at Rackspace.
Affected products
- ScienceLogic SL1 10.1.x, 10.2.x, 11.1.x, 11.2.x, 11.3.x, 12.1.x < 12.1.3, 12.2.x < 12.2.3, 12.3.x < 12.3.0
Timeline
- 2024-09-30: disclosed: Public reports of zero-day exploitation linked to Rackspace breach.
- 2024-10-21: advisory: CVE-2024-9537 published and added to CISA KEV catalog.
- 2024-10-21: kev added