← Vulnerability feed

Vulnerability record · CVE-2020-12812 · published 24 July 2020

CVE-2020-12812: FortiOS SSL VPN two-factor authentication bypass via username case change

Fortinet · Fortios

FortiOS SSL VPN fails to enforce the second authentication factor (FortiToken) when a user alters the letter case of their username. Because the username is treated as a different identity, the MFA check is skipped and the login succeeds with only the password. This undermines the core purpose of two-factor authentication on internet-facing VPN gateways.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 49% · top 1.1% CWE-178 · CWE-178CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
49%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
12 Aug 2026Last modified by NVD

Description

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, and high EPSS make this an actively exploited authentication bypass on internet-facing VPN.

What it is

FortiOS SSL VPN fails to enforce the second authentication factor (FortiToken) when a user alters the letter case of their username. Because the username is treated as a different identity, the MFA check is skipped and the login succeeds with only the password. This undermines the core purpose of two-factor authentication on internet-facing VPN gateways.

Impact

An attacker who already holds valid credentials can log in without the FortiToken second factor, gaining full SSL VPN access with the privileges of the impersonated account. That access can be used to reach internal networks and is linked to ransomware deployment.

Attack surface

Reachable over the network through the SSL VPN login interface (AV:N, PR:N, UI:N). No authentication beyond a valid password is required, and no user interaction is needed; the attacker simply submits the username with different letter casing.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is about 0.49 (98.8th percentile), indicating active exploitation. References are vendor advisories and the CISA KEV entry.

What to do

  • Upgrade FortiOS to a fixed release per Fortinet advisory FG-IR-19-283; 6.4.0, 6.2.0 through 6.2.3, and 6.0.9 and below are affected.
  • Enforce MFA on all SSL VPN accounts and verify the second factor is actually required after patching.
  • Restrict SSL VPN exposure to trusted sources and disable it where not needed.
  • Reset credentials and review sessions for accounts that may have been accessed without the second factor.
  • Monitor Fortinet guidance and KEV for follow-up actions and due dates.

Detection

  • Audit SSL VPN authentication logs for successful logins where the submitted username differs in case from the canonical account name.
  • Alert on successful VPN logins that lack a corresponding FortiToken/MFA success event.
  • Correlate VPN logins with subsequent internal lateral movement or ransomware precursor activity.
  • Review historical VPN logs for the affected versions and time window for anomalous username casing.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-12812 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Fortinet FortiOS SSL VPN Improper Authentication Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Ransomware crews whose documented playbooks reference this CVE: