Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2020-12812

Fortinet | FortiOSAdded 2021-11-03Remediation Deadline 2022-05-03Active Ransomware Campaign

Fortinet FortiOS SSL VPN Improper Authentication Vulnerability

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-178

CWE-287

References