CVE-2020-7388 is a critical unauthenticated remote command execution vulnerability in the AdxDSrv.exe component of Sage X3. By manipulating the client-side authentication request, an attacker can bypass credential validation and execute arbitrary commands as SYSTEM. Exploitation requires knowledge of the installation path, which can be obtained via CVE-2020-7387. The vulnerability is present in on-premises versions of Sage X3 prior to the fixed versions of AdxAdmin 93.2.53 and corresponding Syracuse components.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting Sage X3's AdxAdmin service on Windows. The exploit leverages an authentication bypass (CVE-2020-7388) to execute arbitrary commands as SYSTEM on a vulnerable Sage X3 server. The module connects to the AdxAdmin service (default TCP port 1818), bypasses authentication, and writes payload files (CMD, DLL, or EXE) to the server's temporary directory. It then executes these files, allowing for arbitrary command execution or Meterpreter reverse shells. The module supports multiple payload types and returns command output to the attacker. The code is operational and weaponized for use within the Metasploit framework, with clear targeting of Sage X3 on Windows. The only file in the repository is the exploit module itself, written in Ruby, and structured according to Metasploit conventions.
This repository provides a proof-of-concept exploit for CVE-2020-7388 (and related CVE-2020-7387), targeting the Sage X3 AdxDSrv (AdxAdmin) service. The main exploit is implemented in 'adxsrv_bypass.py', a Python script that connects to the AdxDSrv service (default ports 1818 or 50000) and sends a series of custom protocol messages to achieve unauthenticated remote code execution as SYSTEM. The script allows the user to specify an arbitrary command to run on the target server. The exploit works by leveraging the ADXDIR command to discover the Sage X3 installation path, then stages and executes the payload using temporary files in the AdxAdmin 'tmp' directory. The repository also includes two Nmap NSE scripts: 'x3-adxsrv-vuln.nse' (detects and checks for directory disclosure vulnerability in AdxDSrv) and 'x3-adxsrv.nse' (detects the presence of the AdxDSrv service). These scripts are for detection and reconnaissance, not exploitation. Overall, the repository is a functional PoC for unauthenticated RCE on Sage X3, with clear documentation and code for both exploitation and detection. The attack vector is network-based, requiring access to the AdxDSrv TCP service. The exploit is not weaponized but provides a working example for further development or integration into frameworks.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.