peter bassill · operator
$ cve CVE-2020-12812 JSON

CVE-2020-12812 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 49.3% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS49.34% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-178
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2020-07-24
Last modified2026-08-12

CISA KEV

NameFortinet FortiOS SSL VPN Improper Authentication Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productFortinet / FortiOS
Ransomware useknown

Affected (1)

VendorProduct
fortinetfortios

References

→ the Explorer  ·  watch your stack  ·  NVD