Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
ID: a30ff62d-4a02-53a2-be87-91c0281eded3
STIX ID: report--a30ff62d-4a02-53a2-be87-91c0281eded3
Feed Name: Bleeping Computer
Threat Score
Over 10,000 Fortinet FortiGate firewalls remain unpatched and exposed to active exploitation of CVE-2020-12812, a critical (CVSS 9.8) SSL VPN authentication bypass that allows attackers to circumvent FortiToken 2FA by altering username case; Fortinet, Shadowserver, CISA and the FBI have observed abuse in the wild and linked Fortinet flaws to state-sponsored and ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
