EXPOSURES › CVE-2020-12812
CVE-2020-12812
CRITICAL ⌖ ON CISA KEV · EXPLOITEDFortinet FortiOS allowed unauthorized logins by manipulating username case, bypassing multi-factor authentication (MFA).
A case-sensitive username bypass in FortiOS allowed attackers to circumvent MFA, potentially granting access to sensitive systems. DIB organizations using FortiOS must immediately verify MFA enforcement and user account configurations. This failure highlights the importance of rigorous authentication testing and secure coding practices.
Shame score — The bypass was easily exploitable and directly undermined a key security control (MFA), demonstrating a significant design flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.