CVE-2020-12812This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. It has been observed in ransomware campaigns.
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
Fortinet
FortiOS
See vendor advisoryThis vulnerability was identified in FortiOS by Fortinet. Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
High - Known ransomware exploitation
Complete system compromise possible
https://nvd.nist.gov/vuln/detail/CVE-2020-12812
Apply updates per vendor instructions.
Due Date: 5/3/2022