Fortinet SSL VPN and FortiGate vulnerabilities under active attack

1 min read
Source: The Hacker News
Fortinet SSL VPN and FortiGate vulnerabilities under active attack
Photo: The Hacker News
TL;DR Summary

Fortinet has issued a warning about active exploitation of a five-year-old vulnerability in FortiOS SSL VPN (CVE-2020-12812) that allows attackers to bypass two-factor authentication under certain configurations, especially involving LDAP integration and case-sensitive username matching. Organizations are advised to update their systems or disable username sensitivity to mitigate the risk, and to contact support if they suspect exploitation.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

3 min

vs 4 min read

Condensed

91%

61458 words

Want the full story? Read the original article

Read on The Hacker News