Junglewise Threat Intelligence

CVE-2020-12812: Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

CVE-2020-12812 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Fortinet FortiOS. Vendors: Fortinet.

Executive brief

An improper authentication vulnerability in FortiOS SSL VPN allows a user to bypass two-factor authentication (FortiToken). By changing the case of their username during login, an attacker can successfully authenticate without being prompted for the second factor.

Affected products

  • Fortinet FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below

Timeline

  • 2020-07-24: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported exploited in the wild per advisory summary and CISA KEV entry.

Related threats