ZeroHour

CVE-2024-9537

KEVmoderate

Critical Third-Party Component Flaw in ScienceLogic SL1 Exploited in the Wild

CISA: ScienceLogic SL1 Unspecified Vulnerability

CVSS 4.0
9.3 critical
EPSS
4%p90
Published
()
KEV added
AI analysis

ScienceLogic SL1 (formerly EM7), an enterprise IT infrastructure monitoring platform, is affected by a critical vulnerability (CVSS 4.0: 9.3) in an unspecified third-party component packaged with the product; technical details have not been publicly disclosed. The severity vector (AV:N/AC:L/AT:N/PR:N/UI:N) indicates it can be triggered remotely over the network by an unauthenticated attacker with no user interaction or special conditions. High impacts on confidentiality, integrity, and availability suggest full compromise of the SL1 appliance, giving attackers a foothold in the monitored environment. Any organization running SL1 versions prior to 12.1.3, 12.2.3, or 12.3 — including older 10.1.x through 11.3.x lines — is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-21 following reports of active zero-day exploitation; no public proof-of-concept is known, and whether ransomware groups are leveraging it is unconfirmed.

What to do: Upgrade to SL1 12.1.3+, 12.2.3+, or 12.3+, or apply ScienceLogic's remediations for the 10.1.x–11.3.x lines; per CISA's KEV required action, apply vendor mitigations promptly or discontinue use if mitigations are unavailable. Inventory your SL1 deployments (including appliances managed on behalf of MSP customers), restrict internet exposure of SL1 management interfaces pending patching, and monitor for exploitation activity; ransomware association is not yet confirmed.

Affected
ScienceLogic SL1 (formerly EM7)All versions prior to 12.1.3, 12.2.3, and 12.3; remediations are available for the 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x version lines
Estimated exposure
moderateest. roughly 5,000–10,000 SL1 appliance/VM deployments worldwide — SL1 is a specialized enterprise infrastructure-monitoring platform typically deployed as one or a few centralized appliances or VMs per organization at enterprise and managed-service-provider customers, many of which expose management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.

CISA Known Exploited Vulnerability
Affected
ScienceLogic SL1
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sciencelogic
Products
sl1
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red

In the news