logo

Fortinet VPN design flaw hides successful brute-force attacks

ID: 90b5fbb2-5357-51c0-803b-a7d2e4492f4f

STIX ID: report--90b5fbb2-5357-51c0-803b-a7d2e4492f4f

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-11-21

Date Updated: 2026-03-27

Author: Ionut Ilascu

...
...

Pentera researchers found that FortiClient VPN records successful logins only after both authentication and authorization steps; by halting the process after authentication the server logs only failed attempts, allowing attackers to verify credentials without logging successes. Pentera released a script demonstrating the technique and reported the issue to Fortinet, which did not classify it as a vulnerability; the method increases the risk of stealthy credential validation and potential later unauthorized access despite additional device-compliance checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.