Critical Zero-Day Flaw in ScienceLogic SL1 Under Active Exploitation

Red | Vulnerability Report
Download PDF

CVE-2024-9537 is a critical vulnerability in the ScienceLogic SL1 platform, allowing remote code execution (RCE). This flaw, linked to a third-party utility, was first exploited in an attack on Rackspace in September 2024, leading to the theft of limited monitoring data. ScienceLogic has released patches for affected versions, and organizations are urged to update immediately due to the vulnerability’s CVSS score of 9.8 and its active exploitation.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox