CVE-2020-7389 describes a critical command injection vulnerability in Sage X3 and Sage Syracuse, specifically within the CHAINE variable script. An authenticated developer can exploit this to execute arbitrary OS commands, leading to complete compromise of confidentiality, integrity, and availability. While the CVSS score is 7.2 (HIGH), indicating a severe impact, there is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. Despite this, the vulnerability has garnered some media attention and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0, < 9.22.7.2CPE matchmatch criteria | cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:* | ||
>= 11.0, < 11.25.2.6CPE matchmatch criteria | cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.10.2.8CPE matchmatch criteria | cpe:2.3:a:sage:syracuse:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.