CRITICAL
CVE-2020-12812
CVSS
9.8
KEV
Description
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
Summary dbcve.org
Improper authentication in FortiOS SSL VPN allows bypassing FortiToken two-factor authentication by altering the case of the username during login, enabling unauthorized access to the VPN without completing the second factor.
Mitigation
Upgrade FortiOS to version 6.2.4, 6.4.1, 7.0.0 or later to patch the authentication bypass. Verify that 2FA enforcement is working correctly post-upgrade.
Weakness (CWE)
CWE-178
CWE-287
Improper Authentication
EPSS Score
49.34%
Probability of exploitation in next 30 days
98.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.