CRITICAL

CVE-2020-12812

Fortinet Fortios 2020-07-24 CVSS v3.1
CVSS
9.8
KEV

Description

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

Summary dbcve.org

Improper authentication in FortiOS SSL VPN allows bypassing FortiToken two-factor authentication by altering the case of the username during login, enabling unauthorized access to the VPN without completing the second factor.

Mitigation

Upgrade FortiOS to version 6.2.4, 6.4.1, 7.0.0 or later to patch the authentication bypass. Verify that 2FA enforcement is working correctly post-upgrade.

Weakness (CWE)

CWE-178
CWE-287 Improper Authentication

EPSS Score

49.34%
Probability of exploitation in next 30 days
98.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE