CVE-2020-12812Active Exploitation(fortinet / fortios)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-178CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
fortios

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-05: 1Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-05: 102-05
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Alkor Files@AlkorFiles
    Active Exploitation

    2/8 Fortinet firewalls: CVE-2020-12812 revive. 9.700 expuestos aún. Bypass 2FA con cambio de mayúsculas en usuario LDAP. GoldenJackal y otros lo usan para VPN/admin access. Parche de 2020 ignorado = puertas abiertas https://t.co/pumaImLpHp

    Post summary

    The tweet reports that CVE‑2020‑12812 is actively exploited by actors such as GoldenJackal for VPN/admin access via an LDAP 2FA bypass, while noting that the 2020 patch remains ignored.

    1000037
    20 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
OSfortinetfortios6.4.0--

Explore more