Fortinet has warned customers that threat actors are still actively exploiting a critical FortiOS vulnerability that allows them to bypass two-factor authentication (2FA) when targeting vulnerable FortiGate firewalls. Tracked as CVE-2020-12812, this improper authentication security flaw was found in FortiGate SSL VPN and enables attackers to log in to unpatched firewalls without being prompted for the second factor of authentication (FortiToken) when changing the case of the username. "This happens when two-factor authentication is enabled in the 'user local' setting, and that user authentication type is set to a remote authentication method (eg: ldap)," Fortinet explained when it patched the vulnerability in July 2020. "The issue exists because of inconsistent case sensitive matching among the local and remote authentication." Fortinet released FortiOS versions 6.4.1, 6.2.4, and 6.0.10 in July 2020 to address this flaw and advised IT admins who can't deploy the security update to turn off username-case-sensitivity to avoid the 2FA bypass issue. Last week, the company warned customers that attackers are still exploiting CVE-2020-12812 in the wild, targeting firewalls with LDAP (Lightweight Directory Access Protocol) enabled. However, to be vulnerable to these ongoing attacks, organizations must have local user entries on the FortiGate that require two-factor authentication (2FA) and are linked to LDAP. Additionally, these users must belong to an LDAP group, which must also b...
Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Dec 29, 2025
·Updated
Affected Software
1 affected component
Fortinet FortiGate>=6.0.10, >=6.2.4, >=6.4.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in FortiOS that allows bypassing two-factor authentication on FortiGate firewalls.
2
What security implications are discussed in the article?
The article highlights ongoing exploitation of a five-year-old vulnerability, which poses a risk to the security of organizations using affected FortiGate products.
3
What products or software are affected by this vulnerability?
The vulnerability affects Fortinet FortiGate firewalls running specific versions of FortiOS, namely 6.0.10 and above, 6.2.4 and above, and 6.4.1 and above.
4
Who is at risk from the exploitation of this FortiOS vulnerability?
Organizations and businesses using vulnerable versions of FortiGate firewalls are at risk of attacks targeting the bypassing of two-factor authentication.
5
What should users of FortiGate firewalls do in response to this threat?
Users should review their systems for the affected versions of FortiOS and apply any necessary security updates or patches recommended by Fortinet.