CVE-2024-9537
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- ScienceLogic SL1 Unspecified Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
9.3 (CRITICAL)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red - EPSS — סבירות ניצול
- 4% (אחוזון 100) נכון ל-26/7/2026
מוצרים מושפעים
sciencelogic: sl1
קישורים
- https://community.sciencelogic.com/blog/latest-kb-articles-and-known-issues-bl… Vendor Advisory
- https://arcticwolf.com/resources/blog/rackspace-breach-linked-to-zero-day-vuln… Press/Media Coverage
- https://rackspace.service-now.com/system_status?id=detailed_status&service=4da… Third Party Advisory
- https://support.sciencelogic.com/s/article/15465 Permissions Required
- https://support.sciencelogic.com/s/article/15527 Permissions Required
- https://twitter.com/ynezzor/status/1839931641172467907 Third Party Advisory
- https://www.bleepingcomputer.com/news/security/rackspace-monitoring-data-stole… Press/Media Coverage
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fullte… Third Party AdvisoryUS Government Resource
- https://www.theregister.com/2024/09/30/rackspace_zero_day_attack/ Press/Media Coverage
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource