Umbra Wiki cve cve/CVE-2020-12812
Back to wiki

CVE-2020-12812 — Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

provenance: imported · CVE: CVE-2020-12812

CVE-2020-12812: Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Fortinet
Product FortiOS
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Known

Description

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-12812

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-12812
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog