Improper Authentication in FortiOS - CVE-2020-12812
Published: July 16, 2020 / Updated: January 5, 2026
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in SSL VPN. A remote authenticated attacker can changed the case of their username and gain unauthorized access to the application without being prompted for the second factor of authentication (FortiToken).