Skip to content
COOEY

EXPOSURES › CVE-2020-12812

CVE-2020-12812

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-12812 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildauth-bypassunpatched

Fortinet FortiOS allowed unauthorized logins by manipulating username case, bypassing multi-factor authentication (MFA).

A case-sensitive username bypass in FortiOS allowed attackers to circumvent MFA, potentially granting access to sensitive systems. DIB organizations using FortiOS must immediately verify MFA enforcement and user account configurations. This failure highlights the importance of rigorous authentication testing and secure coding practices.

Shame score — The bypass was easily exploitable and directly undermined a key security control (MFA), demonstrating a significant design flaw.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -0.70
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.