CVE-2025-4320
Information Disclosure in Birebirsoft's Sufirmam
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 10EPSS 0.5%KEV nãoPoC —Patch —
Ciclo de vida
23 ene 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation.
This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
Birebirsoft Software and Technology Solutions · Sufirmam¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →