• News/
  • https://www.bleepingcomputer.com/news/security/fortinet-warns-of-5-year-old-fortios-2fa-bypass-still-exploited-in-attacks/

Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 29, 2025
·
Updated

Fortinet has warned customers that threat actors are still actively exploiting a critical FortiOS vulnerability that allows them to bypass two-factor authentication (2FA) when targeting vulnerable FortiGate firewalls. Tracked as CVE-2020-12812, this improper authentication security flaw was found in FortiGate SSL VPN and enables attackers to log in to unpatched firewalls without being prompted for the second factor of authentication (FortiToken) when changing the case of the username. "This happens when two-factor authentication is enabled in the 'user local' setting, and that user authentication type is set to a remote authentication method (eg: ldap)," Fortinet explained when it patched the vulnerability in July 2020. "The issue exists because of inconsistent case sensitive matching among the local and remote authentication." Fortinet released FortiOS versions 6.4.1, 6.2.4, and 6.0.10 in July 2020 to address this flaw and advised IT admins who can't deploy the security update to turn off username-case-sensitivity to avoid the 2FA bypass issue. Last week, the company warned customers that attackers are still exploiting CVE-2020-12812 in the wild, targeting firewalls with LDAP (Lightweight Directory Access Protocol) enabled. However, to be vulnerable to these ongoing attacks, organizations must have local user entries on the FortiGate that require two-factor authentication (2FA) and are linked to LDAP. Additionally, these users must belong to an LDAP group, which must also b...

Read full article

Affected Software

1 affected component
Fortinet FortiGate>=6.0.10, >=6.2.4, >=6.4.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in FortiOS that allows bypassing two-factor authentication on FortiGate firewalls.

2

What security implications are discussed in the article?

The article highlights ongoing exploitation of a five-year-old vulnerability, which poses a risk to the security of organizations using affected FortiGate products.

3

What products or software are affected by this vulnerability?

The vulnerability affects Fortinet FortiGate firewalls running specific versions of FortiOS, namely 6.0.10 and above, 6.2.4 and above, and 6.4.1 and above.

4

Who is at risk from the exploitation of this FortiOS vulnerability?

Organizations and businesses using vulnerable versions of FortiGate firewalls are at risk of attacks targeting the bypassing of two-factor authentication.

5

What should users of FortiGate firewalls do in response to this threat?

Users should review their systems for the affected versions of FortiOS and apply any necessary security updates or patches recommended by Fortinet.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203