Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks
ID: 425d94ce-cf2e-561e-b46d-b1fb6a510773
STIX ID: report--425d94ce-cf2e-561e-b46d-b1fb6a510773
Feed Name: Bleeping Computer
Threat Score
Fortinet warns that CVE-2020-12812, an improper authentication flaw in FortiGate SSL VPNs, is being actively exploited to bypass FortiToken two-factor authentication by changing username case; patches and mitigation guidance were released in July 2020. Recent activity includes attacks against LDAP-configured appliances, involvement of state-backed actors and ransomware misuse, and advisories from FBI/CISA with CISA adding the CVE to its known exploited vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
