ScienceLogic SL1 unspecified vulnerability
Published Oct 18, 2024 ·Due Nov 11, 2024
9.3
CRITICALCVSS 4.0
EPSS 3.83%
Description
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.
Affected products
-
- Version 0StatusaffectedConstraints<10.1.x
- Version 0StatusaffectedConstraints<10.2.x
- Version 0StatusaffectedConstraints<11.1.x
- Version 0StatusaffectedConstraints<11.2.x
- Version 0StatusaffectedConstraints<11.3.x
- Version 0StatusaffectedConstraints<12.1.3
- Version 0StatusaffectedConstraints<12.2.3
- Version 0StatusaffectedConstraints<12.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ScienceLogic | SL1 | n/a |
|
- ≥ 10.1.0 · < 12.1.3
- ≥ 12.2.0 · < 12.2.3
-
- Version 0StatusaffectedConstraints<10.1.x
- Version 0StatusaffectedConstraints<10.2.x
- Version 0StatusaffectedConstraints<11.1.x
- Version 0StatusaffectedConstraints<11.2.x
- Version 0StatusaffectedConstraints<11.3.x
- Version 0StatusaffectedConstraints<12.1.3
- Version 0StatusaffectedConstraints<12.2.3
- Version 0StatusaffectedConstraints<12.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Sciencelogic | Sl1 | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (11)
- https://arcticwolf.com/resources/blog/rackspace-breach-linked-to-zero-day-vulnerability-sciencelogic-sl1s-third-party-utility/ third-party-advisoryPress/Media Coverage
- https://community.sciencelogic.com/blog/latest-kb-articles-and-known-issues-blog-board/week-of-september-30-2024---latest-kb-articles-and-known-issues-part-1-of-2/1690 release-notesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49996 Advisory
- https://rackspace.service-now.com/system_status?id=detailed_status&service=4dafca5a87f41610568b206f8bbb35a6 Third Party Advisory
- https://support.sciencelogic.com/s/article/15465 vendor-advisoryPermissions Required
- https://support.sciencelogic.com/s/article/15527 vendor-advisoryPermissions Required
- https://twitter.com/ynezzor/status/1839931641172467907 Third Party Advisory
- https://www.bleepingcomputer.com/news/security/rackspace-monitoring-data-stolen-in-sciencelogic-zero-day-attack/ media-coveragePress/Media Coverage
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9537 government-resourceUS Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-9537 government-resourceThird Party AdvisoryUS Government Resource
- https://www.theregister.com/2024/09/30/rackspace_zero_day_attack/ media-coveragePress/Media Coverage
Change history (0)
No recorded changes yet.