SB20200716117 - Improper Authentication in Fortinet FortiOS 



SB20200716117 - Improper Authentication in Fortinet FortiOS

Published: July 16, 2020 Updated: January 5, 2026

Security Bulletin ID SB20200716117
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2020-12812)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests in SSL VPN. A remote authenticated attacker can changed the case of their username and gain unauthorized access to the application without being prompted for the second factor of authentication (FortiToken).


Remediation

Install update from vendor's website.