vulnerability

Fortinet FortiOS: Improper Authentication (CVE-2020-12812)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Jul 24, 2020
Added
Jul 30, 2020
Modified
Feb 15, 2024

Description

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

Solution(s)

fortios-upgrade-6_0_10fortios-upgrade-6_2_4
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.