Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-12812

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.495
EPSS Ranking 97.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Proposed Action
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
Ransomware Campaign
Known
Products affected by CVE-2020-12812


Contact Us

Shodan ® - All rights reserved