CVE-2024-9537

CRITICAL(9.8)KEV

ScienceLogic SL1 Unspecified Vulnerability

Description

CVE-2024-9537 is a critical vulnerability in ScienceLogic SL1 (formerly EM7) involving an unspecified third-party component packaged with the platform that allows remote, unauthenticated attackers to compromise the system. With a CVSS v3.1 base score of 9.8 (CRITICAL), the vulnerability requires no authentication or user interaction and was exploited as a zero-day in attacks against Rackspace's internal monitoring infrastructure. CISA has added CVE-2024-9537 to the Known Exploited Vulnerabilities catalog with a remediation deadline of November 11, 2024, and its EPSS score of 63.91% at the 98.4th percentile indicates significant active exploitation.

KEV Information

Vendor
ScienceLogic
Product
SL1
Date Added
October 21, 2024
Due Date
November 11, 2024
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

Affected Products

VendorProductVersion
sciencelogicsl1>= 10.1.0, < 12.1.3; >= 12.2.0, < 12.2.3

Multiple CVSS Assessments

Source: 9119a7d8-5eab-497f-8521-727c672e3725(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

Unspecified Third-Party Component Vulnerability

ScienceLogic has not disclosed the specific CWE classification or the identity of the vulnerable third-party component in CVE-2024-9537. The vulnerability resides in a bundled third-party utility within the SL1 platform, and the deliberate vagueness around the component suggests a coordinated disclosure effort to protect other products that may ship the same component. Based on the attack characteristics observed in the Rackspace breach, the vulnerability enables remote code execution through the third-party component without authentication.

Learn more: ScienceLogic Security Advisory

Impact Analysis

The impact of CVE-2024-9537 is severe, with Confidentiality (High), Integrity (High), and Availability (High) fully compromised. The attack is network-accessible (AV:N) with low complexity (AC:L), requires no privileges (PR:N) and no user interaction (UI:N), making it trivially exploitable against any exposed SL1 instance. ScienceLogic SL1 is an IT infrastructure monitoring platform that typically has deep access to internal networks, SNMP credentials, API keys, and monitoring data for servers, network devices, and cloud services. A compromise of the SL1 platform gives attackers visibility into the entire monitored infrastructure and access to stored credentials used for monitoring. The real-world impact was demonstrated in the Rackspace breach, where attackers exploited this zero-day to access Rackspace's internal monitoring systems and steal customer monitoring data including hostnames, IP addresses, and device information. The EPSS score of 63.91% at the 98.4th percentile confirms ongoing exploitation activity. While the ransomware nexus is listed as Unknown, the monitoring platform's strategic position makes it an ideal pivot point for advanced persistent threat operations.

Exploit Maturity

CVE-2024-9537 was exploited as a zero-day vulnerability before any patch was available, demonstrating maximum exploit maturity. CISA confirmed active exploitation by adding it to the Known Exploited Vulnerabilities catalog with a remediation deadline of November 11, 2024. The EPSS score of 63.91% at the 98.4th percentile indicates active exploitation campaigns. The vulnerability gained public attention through the Rackspace breach reported by Arctic Wolf and covered by BleepingComputer and The Register. The zero-day exploitation against a major cloud provider demonstrates that sophisticated threat actors had weaponized this vulnerability before it was publicly known. The deliberate concealment of the specific vulnerable component suggests the issue may affect other products beyond SL1.

Remediation

  1. Upgrade ScienceLogic SL1 immediately to version 12.1.3 or later, 12.2.3 or later, or 12.3 or later. ScienceLogic has also released remediations for older version lines including 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x as detailed in the ScienceLogic community advisory.

  2. Restrict network access to SL1 instances by ensuring that the SL1 management interface and APIs are not exposed to the internet. Place SL1 behind a VPN or restrict access to specific management network segments using firewall rules.

  3. Audit monitoring data and credentials stored in SL1, as attackers may have exfiltrated SNMP community strings, API credentials, SSH keys, and other secrets used for monitoring. Rotate all credentials that SL1 uses to connect to monitored devices and services.

  4. Review SL1 access logs and system activity for indicators of compromise including unauthorized access, unusual API calls, data exports, and modifications to monitoring configurations. Check for evidence of lateral movement from the SL1 platform to monitored infrastructure.

  5. Implement network monitoring for anomalous SL1 traffic including unexpected outbound connections, large data transfers, and connections to unfamiliar IP addresses. The monitoring platform itself should be monitored for compromise indicators given its privileged network position.

Technical Details

CVE-2024-9537 is a critical vulnerability in a third-party component bundled with ScienceLogic SL1. The CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H reflects a network-accessible (AV:N), low-complexity (AC:L) attack requiring no privileges (PR:N) and no user interaction (UI:N), with Unchanged scope (S:U) and maximum impact across all three pillars. ScienceLogic has deliberately withheld technical details about the specific vulnerable component to prevent further exploitation and protect other products that may include the same library. The vulnerability was exploited as a zero-day in the Rackspace breach, where attackers gained access to the SL1 monitoring infrastructure without authentication. SL1 is deployed as a virtual appliance or physical server that monitors IT infrastructure via SNMP, SSH, WMI, APIs, and other protocols. The platform stores credentials for all monitored systems and has network visibility into the entire monitored environment. The combination of an unauthenticated remote vulnerability in a platform with such privileged access makes this exceptionally dangerous. Affected versions span from 10.1.0 through 12.2.2, covering years of SL1 deployments.

Frequently Asked Questions

Is CVE-2024-9537 being actively exploited?

Yes, CVE-2024-9537 was exploited as a zero-day in a high-profile breach of Rackspace's internal monitoring infrastructure. CISA added it to the Known Exploited Vulnerabilities catalog, and the EPSS score of 63.91% at the 98.4th percentile confirms ongoing exploitation.

What products are affected by CVE-2024-9537?

ScienceLogic SL1 (formerly EM7) versions from 10.1.0 through 12.2.2 are affected. This includes all SL1 deployments that have not been updated to versions 12.1.3, 12.2.3, or 12.3 and later. Older version lines 10.1.x through 11.3.x have also received specific patches.

How do I fix CVE-2024-9537?

Upgrade SL1 to version 12.1.3+, 12.2.3+, or 12.3+. For older installations, apply the version-specific remediations from ScienceLogic. Restrict network access to the SL1 management interface and rotate all monitoring credentials.

What was the Rackspace breach related to CVE-2024-9537?

Attackers exploited CVE-2024-9537 as a zero-day to compromise Rackspace's ScienceLogic SL1 monitoring infrastructure. The breach resulted in theft of internal monitoring data including customer hostnames, IP addresses, and device information. Rackspace disclosed the incident and worked with ScienceLogic to develop and release patches.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score3.83%
EPSS Percentile89.2%

Dates

PublishedOctober 18, 2024
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.