CyberSec.Space Logo
Back to CVE Browser

CVE-2020-12812

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score71.9550%
EPSS Percentile85.38th
PublishedJul 24, 2020
Last ModifiedOct 24, 2025

Vulnerability Description

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

Affected Platforms (CPE)

πŸ’»
Fortinet

Fortios

< 6.0.10
πŸ’»
Fortinet

Fortios

>= 6.2.0 and < 6.2.4
πŸ’»
Fortinet

Fortios

= 6.4.0

References & Advisories

Related Vulnerabilities