CVE-2020-12812
CVE Published | 2020-07-24 |
---|---|
Related CWE(s) | CWE-287: Improper Authentication, CWE-178: Improper Handling of Case Sensitivity |
Related Vendor(s) | fortinet |
Related Product(s) | fortios |
Exploitation Reported (CISA KEV) | 2021-11-03 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph
Threat Reports Related to CVE-2020-12812
Report
#StopRansomware: Play Ransomware
This is a Cybersecurity Advisory from CISA with US and international partners which outlines TTPs (tactics, techniques and procedures) and IoCs ...