← Back to browse · API

CVE-2020-12812

Severity
CRITICAL
CVSS
9.8
EPSS
0.49344
Risk score
81.47
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-5095, GHSA-R9CJ-Q2HJ-HFQ9
Products
Fortinet:FortiOS, Fortinet:Fortinet FortiOS FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below
Sources
euvd EUVD-2020-5095
cisa.gov CVE-2020-12812

Description

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

References