Vulnerability record · CVE-2024-9537 · published 18 October 2024
CVE-2024-9537: ScienceLogic SL1 third-party component flaw allows unauthenticated remote compromise
Sciencelogic · Sl1
ScienceLogic SL1 (formerly EM7) contains an unspecified vulnerability in an unspecified third-party component packaged with the product. The flaw is remotely reachable without authentication and rated CVSS 4.0 9.3 Critical, and it was exploited as a zero-day in the Rackspace breach. Because the vulnerable component and root cause are not disclosed, defenders must rely on vendor patching rather than signature-level understanding.
Description
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 9.3 unauthenticated network-exploitable flaw with confirmed zero-day exploitation and CISA KEV listing, though the undisclosed component limits precise detection.
What it is
ScienceLogic SL1 (formerly EM7) contains an unspecified vulnerability in an unspecified third-party component packaged with the product. The flaw is remotely reachable without authentication and rated CVSS 4.0 9.3 Critical, and it was exploited as a zero-day in the Rackspace breach. Because the vulnerable component and root cause are not disclosed, defenders must rely on vendor patching rather than signature-level understanding.
Impact
An unauthenticated remote attacker can achieve high confidentiality, integrity and availability impact on the SL1 host, potentially leading to full compromise of the monitoring platform and data it holds. In the observed incident, monitoring data was stolen.
Attack surface
Reachable over the network per the CVSS vector (AV:N/AC:L/PR:N/UI:N), so no authentication or user interaction is required. The specific exposed interface is not identified in the record because the vulnerable third-party component is unspecified.
Exploitation
CVE-2024-9537 is listed in CISA KEV (added 2024-10-21, due 2024-11-11) and press reporting links it to a zero-day used in the Rackspace breach; EPSS 30-day probability is 0.038 (89.5th percentile). No ransomware campaign use is recorded.
What to do
- Upgrade SL1 to 12.1.3+, 12.2.3+, or 12.3+ immediately; apply the vendor remediations provided for older lines 10.1.x, 10.2.x, 11.1.x, 11.2.x and 11.3.x.
- If patching cannot be completed by the CISA KEV due date (2024-11-11), isolate or discontinue use of the affected SL1 deployment per CISA guidance.
- Restrict network access to SL1 management and component interfaces to trusted administrative networks only.
- Review vendor KB articles (support.sciencelogic.com article 15465 and 15527) for component-specific guidance, noting they require support credentials.
- Monitor vendor advisories for disclosure of the affected third-party component so compensating controls can be targeted.
Detection
- Hunt for unexpected outbound or inbound network connections to and from SL1 hosts, especially to unfamiliar external addresses.
- Review SL1 host logs and process execution for activity tied to bundled third-party utilities, since the vulnerable component is unspecified.
- Correlate SL1 host telemetry with authentication and data-access logs for anomalous access to monitoring data.
- Track CISA KEV and vendor advisory updates for the component name to build targeted detections once disclosed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-9537 to the Known Exploited Vulnerabilities catalog on 21 October 2024 as "ScienceLogic SL1 Unspecified Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 November 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-9537 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-9537), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.