logo

Product Security Advisory and Analysis: Observed Abuse of FG-IR-19-283

ID: 0080c332-4482-53e6-b5e4-9068bfeee6d7

STIX ID: report--0080c332-4482-53e6-b5e4-9068bfeee6d7

Feed Name: Fortinet Blog

Threat Score
70/100

Date Published: 2025-12-24

Date Updated: 2026-04-27

...
...

Fortinet warns of CVE-2020-12812 (FG-IR-19-283): when FortiGate treats usernames as case-sensitive but the LDAP directory does not, users can bypass locally configured 2FA by using different-cased usernames, causing authentication to fall back to LDAP and succeed without tokens. The advisory describes affected configurations, reproduction steps, observed abuse, and recommends upgrading to fixed FortiOS releases or disabling username case-sensitivity with provided configuration commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.