Executive brief
Birebirsoft Sufirmam contains a critical security flaw in its login and password recovery systems. The software fails to limit the number of failed login attempts and uses a weak process for resetting forgotten passwords. This allows unauthorized individuals to gain access to user accounts through automated guessing attacks, potentially leading to the theft of sensitive corporate data or complete account takeover.
Technical details
The vulnerability consists of two primary weaknesses: CWE-307 (Improper Restriction of Excessive Authentication Attempts) and CWE-640 (Weak Password Recovery Mechanism for Forgotten Password). The Sufirmam application does not implement adequate rate limiting or account lockout policies, enabling remote, unauthenticated attackers to perform high-volume brute force attacks against the login interface. Additionally, the password recovery workflow is insufficiently secured, allowing attackers to exploit the reset process to gain unauthorized access to accounts. The vulnerability is reachable over the network without user interaction. As of the disclosure date, the vendor has not responded to reports or provided a patch.
Affected products
- Birebirsoft Software and Technology Solutions Sufirmam through 23012026
Timeline
- 2026-01-23: advisory: Initial disclosure by TR-CERT (USOM)
- 2026-01-23: disclosed: CVE published to NVD