ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero

criticalVulnerability exploited in the wildimportance 60CVE-2024-9537CVE-2024-23113

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-23113
Format String Vulnerability Enables Unauthenticated RCE in Fortinet FortiOS and FortiProxy

CVE-2024-23113 is a use of externally-controlled format string (CWE-134) in multiple Fortinet products, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specially crafted packets to an affected device. The flaw carries a critical CVSS 3.1 score of 9.8 (network vector, no privileges or user interaction required, high impact on confidentiality, integrity, and availability). It affects FortiOS 7.0.0 through 7.0.13, 7.2.0 through 7.2.6, and 7.4.0 through 7.4.2; FortiProxy 7.0.0 through 7.0.14, 7.2.0 through 7.2.8, and 7.4.0 through 7.4.2; FortiPAM 1.0.0 through 1.0.3, 1.1.0 through 1.1.2, and 1.2.0; and FortiSwitchManager 7.0.0 through 7.0.3 and 7.2.0 through 7.2.3. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-10-09 and warns it is likely being exploited in the wild, though no public proof-of-concept is known. Scanning coverage reported in the trade press indicates roughly 87,000 or more internet-exposed Fortinet devices remained vulnerable and open to attack after disclosure.

Do: Upgrade affected FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager deployments to a patched release per Fortinet's advisory, since the data does not specify fixed build numbers. Until patching is complete, restrict management interface access to trusted sources, minimize internet exposure of affected devices, and verify your version falls within the affected ranges above. Treat this as an actively exploited vulnerability per CISA's KEV listing (added 2024-10-09) and prioritize it accordingly.

9.862% KEV
  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14
  • Fortinet FortiPAM 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3
  • +1 more
large≈87,000+ internet-exposed Fortinet devices per public scans (FortiOS/FortiProxy deployments; total installed base larger, affected-version share unknown)
CVE-2024-9537
Critical Third-Party Component Flaw in ScienceLogic SL1 Exploited in the Wild

ScienceLogic SL1 (formerly EM7), an enterprise IT infrastructure monitoring platform, is affected by a critical vulnerability (CVSS 4.0: 9.3) in an unspecified third-party component packaged with the product; technical details have not been publicly disclosed. The severity vector (AV:N/AC:L/AT:N/PR:N/UI:N) indicates it can be triggered remotely over the network by an unauthenticated attacker with no user interaction or special conditions. High impacts on confidentiality, integrity, and availability suggest full compromise of the SL1 appliance, giving attackers a foothold in the monitored environment. Any organization running SL1 versions prior to 12.1.3, 12.2.3, or 12.3 — including older 10.1.x through 11.3.x lines — is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-21 following reports of active zero-day exploitation; no public proof-of-concept is known, and whether ransomware groups are leveraging it is unconfirmed.

Do: Upgrade to SL1 12.1.3+, 12.2.3+, or 12.3+, or apply ScienceLogic's remediations for the 10.1.x–11.3.x lines; per CISA's KEV required action, apply vendor mitigations promptly or discontinue use if mitigations are unavailable. Inventory your SL1 deployments (including appliances managed on behalf of MSP customers), restrict internet exposure of SL1 management interfaces pending patching, and monitor for exploitation activity; ransomware association is not yet confirmed.

9.34% KEV
  • ScienceLogic SL1 (formerly EM7) All versions prior to 12.1.3, 12.2.3, and 12.3; remediations are available for the 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x version lines
moderateest. roughly 5,000–10,000 SL1 appliance/VM deployments worldwide
Full article478 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 22, 2024Vulnerability / Cyber Threat

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation as a zero-day.

The vulnerability in question, tracked as CVE-2024-9537 (CVSS v4 score: 9.3), refers to a bug involving an unspecified third-party component that could lead to remote code execution.

The issue has since been addressed in versions 12.1.3, 12.2.3, and 12.3 and later. Fixes have also been made available for version 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.

The development comes weeks after cloud hosting provider Rackspace acknowledged that it "became aware of an issue with the ScienceLogic EM7 Portal," prompting it to take its dashboard offline towards the end of last month.

"We have confirmed that the exploit of this third-party application resulted in access to three internal Rackspace monitoring web servers," an account named ynezzor said in an X post on September 28, 2024.

It's not clear who is behind the attack, although Rackspace has confirmed to Bleeping Computer that the zero-day exploitation led to unauthorized access to its internal performance reporting systems and that it has notified all impacted customers. The breach was first reported by The Register.

Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by November 11, 2024, to counter possible threats to their networks.

Fortinet Patches Likely Exploited Flaw

The development comes as Fortinet has released security updates for FortiManager to remediate a vulnerability that is reportedly being exploited by China-linked threat actors.

Details about the flaw are presently unknown, although Fortinet, in the past, has sent out confidential customer communications in advance to help them bolster their defenses prior to it being released to a broader audience. The Hacker News has reached out to the company, and we will update the story if we hear back.

"FortiGate have released one of the six new versions of FortiManager which fix the actively exploited zero day in the product... but they've not issued a CVE or documented the issue existing in the release notes. Next week maybe?," security researcher Kevin Beaumont said on Mastodon.

"Fortigate currently having the world's least secret zero day used by China play out, including in FortiManager Cloud... but everybody is confused."

Beaumont, who has given the flaw the moniker FortiJump, said the vulnerability likely resides in the FortiGate to FortiManager (FGFM) protocol. A search on the Shodan search engine shows close to 60,000 instances that are exposed to the internet.

Earlier this month, CISA added another critical flaw impacting Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb (CVE-2024-23113, CVSS score: 9.8) to its KEV catalog, based on evidence of in-the-wild exploitation.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/cisa-adds-sciencelogic-sl1.html