CVE-2024-9537
KEVmoderateCritical Third-Party Component Flaw in ScienceLogic SL1 Exploited in the Wild
CISA: ScienceLogic SL1 Unspecified Vulnerability
ScienceLogic SL1 (formerly EM7), an enterprise IT infrastructure monitoring platform, is affected by a critical vulnerability (CVSS 4.0: 9.3) in an unspecified third-party component packaged with the product; technical details have not been publicly disclosed. The severity vector (AV:N/AC:L/AT:N/PR:N/UI:N) indicates it can be triggered remotely over the network by an unauthenticated attacker with no user interaction or special conditions. High impacts on confidentiality, integrity, and availability suggest full compromise of the SL1 appliance, giving attackers a foothold in the monitored environment. Any organization running SL1 versions prior to 12.1.3, 12.2.3, or 12.3 — including older 10.1.x through 11.3.x lines — is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-21 following reports of active zero-day exploitation; no public proof-of-concept is known, and whether ransomware groups are leveraging it is unconfirmed.
What to do: Upgrade to SL1 12.1.3+, 12.2.3+, or 12.3+, or apply ScienceLogic's remediations for the 10.1.x–11.3.x lines; per CISA's KEV required action, apply vendor mitigations promptly or discontinue use if mitigations are unavailable. Inventory your SL1 deployments (including appliances managed on behalf of MSP customers), restrict internet exposure of SL1 management interfaces pending patching, and monitor for exploitation activity; ransomware association is not yet confirmed.
| ScienceLogic SL1 (formerly EM7) | All versions prior to 12.1.3, 12.2.3, and 12.3; remediations are available for the 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x version lines |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.
- Affected
- ScienceLogic SL1
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sciencelogic
- Products
- sl1
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red