← KEV catalog
CISA known exploited vulnerability

CVE-2020-12812

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

SOURCE FACT

Fortinet · FortiOS

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-12812

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?