A AegiFlow
CRITICALCVSS 9.8KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2020-12812

CVE-2020-12812 updated by NVD

Published
2021-11-03
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.