← Vulnerability feed

Vulnerability record · CVE-2024-9537 · published 18 October 2024

CVE-2024-9537: ScienceLogic SL1 third-party component flaw allows unauthenticated remote compromise

Sciencelogic · Sl1

ScienceLogic SL1 (formerly EM7) contains an unspecified vulnerability in an unspecified third-party component packaged with the product. The flaw is remotely reachable without authentication and rated CVSS 4.0 9.3 Critical, and it was exploited as a zero-day in the Rackspace breach. Because the vulnerable component and root cause are not disclosed, defenders must rely on vendor patching rather than signature-level understanding.

9.3 CVSS 4.0 Critical CISA KEV since 21 Oct 2024 EPSS 3.8% · top 10.3%
9.3CVSS 4.0 base score
3.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.3 unauthenticated network-exploitable flaw with confirmed zero-day exploitation and CISA KEV listing, though the undisclosed component limits precise detection.

What it is

ScienceLogic SL1 (formerly EM7) contains an unspecified vulnerability in an unspecified third-party component packaged with the product. The flaw is remotely reachable without authentication and rated CVSS 4.0 9.3 Critical, and it was exploited as a zero-day in the Rackspace breach. Because the vulnerable component and root cause are not disclosed, defenders must rely on vendor patching rather than signature-level understanding.

Impact

An unauthenticated remote attacker can achieve high confidentiality, integrity and availability impact on the SL1 host, potentially leading to full compromise of the monitoring platform and data it holds. In the observed incident, monitoring data was stolen.

Attack surface

Reachable over the network per the CVSS vector (AV:N/AC:L/PR:N/UI:N), so no authentication or user interaction is required. The specific exposed interface is not identified in the record because the vulnerable third-party component is unspecified.

Exploitation

CVE-2024-9537 is listed in CISA KEV (added 2024-10-21, due 2024-11-11) and press reporting links it to a zero-day used in the Rackspace breach; EPSS 30-day probability is 0.038 (89.5th percentile). No ransomware campaign use is recorded.

What to do

  • Upgrade SL1 to 12.1.3+, 12.2.3+, or 12.3+ immediately; apply the vendor remediations provided for older lines 10.1.x, 10.2.x, 11.1.x, 11.2.x and 11.3.x.
  • If patching cannot be completed by the CISA KEV due date (2024-11-11), isolate or discontinue use of the affected SL1 deployment per CISA guidance.
  • Restrict network access to SL1 management and component interfaces to trusted administrative networks only.
  • Review vendor KB articles (support.sciencelogic.com article 15465 and 15527) for component-specific guidance, noting they require support credentials.
  • Monitor vendor advisories for disclosure of the affected third-party component so compensating controls can be targeted.

Detection

  • Hunt for unexpected outbound or inbound network connections to and from SL1 hosts, especially to unfamiliar external addresses.
  • Review SL1 host logs and process execution for activity tied to bundled third-party utilities, since the vulnerable component is unspecified.
  • Correlate SL1 host telemetry with authentication and data-access logs for anomalous access to monitoring data.
  • Track CISA KEV and vendor advisory updates for the component name to build targeted detections once disclosed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-9537 to the Known Exploited Vulnerabilities catalog on 21 October 2024 as "ScienceLogic SL1 Unspecified Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 November 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9537 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-48601Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and p…EPSS 0.73%8.8CVE-2022-48602Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and p…EPSS 0.73%8.8CVE-2022-48603Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and …EPSS 0.73%8.8CVE-2022-48604Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes …EPSS 0.73%8.8CVE-2022-48592Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsaniti…EPSS 0.73%8.8CVE-2022-48593Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and …EPSS 0.72%8.8CVE-2022-48594Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and …EPSS 0.73%8.8CVE-2022-48595Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input a…EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2024-9537), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.