Tag: SL1 Vulnerability

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack
News

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack

Following indications of active exploitation as a zero-day vulnerability, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical security issue affecting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) database on Monday. Tracked as CVE-2024-9537 (CVSS v4 score: 9.3), the vulnerability in question is a flaw involving an unidentified third-party component that may allow remote code execution. Since then, versions 12.1.3, 12.2.3, 12.3, and later have fixed the problem. Additionally, fixes for versions 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x are now available. The change occurred a few weeks after cloud hosting company Rackspace said it discovered a problem with the ScienceLogic EM7 Portal read more about CISA Adds ScienceLogic SL1 Vulnera...