#cve-2020-12812

[ follow ]
Information security
fromTechzine Global
4 days ago

Attackers exploit five-year-old Fortinet vulnerability

A critical FortiOS SSL VPN flaw (CVE-2020-12812) allows 2FA bypass via username changes; patches have existed since 2020 but many systems remain unpatched.
Information security
fromThe Hacker News
1 week ago

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

CVE-2020-12812 allows LDAP users with 2FA on FortiGate SSL VPN to bypass second-factor authentication when username case mismatches under specific configurations.
[ Load more ]