{"id":"CVE-2020-12812","title":"An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…","summary":"An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-178","CWE-287","CWE-287"],"vendor":"fortinet","product":"fortios","affected":["fortios < 6.0.10","fortios >= 6.2.0, < 6.2.4","fortios = 6.4.0"],"patched":["fortios 6.2.4"],"published":"2020-07-24","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-12812","references":[{"url":"https://fortiguard.com/psirt/FG-IR-19-283","label":"psirt@fortinet.com"},{"url":"https://fortiguard.com/psirt/FG-IR-19-283","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-12812","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.49344,"epssPercentile":0.9887,"kev":true,"kevDateAdded":"2021-11-03","kevDueDate":"2022-05-03","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-12T05:52:07.582Z","slug":"CVE-2020-12812","body":"## Overview\n\nAn improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.\n\n## Affected\n\n- `fortios < 6.0.10`\n- `fortios >= 6.2.0, < 6.2.4`\n- `fortios = 6.4.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortios 6.2.4`","depth":"hadal","depthScore":94,"depthScoreParts":{"impact":53.9,"likelihood":9.9,"exploitation":25,"ransomware":5},"changes":[]}