Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
A five-year-old major two-factor authentication (2FA) bypass flaw leaves over 10,000 Fortinet firewalls open to continuous attacks.
In order to fix this vulnerability (recorded as CVE-2020-12812), Fortinet published FortiOS versions 6.4.1, 6.2.4, and 6.0.10 in July 2020. Administrators who were unable to patch the issue right away were recommended to disable username-case-sensitivity in order to prevent efforts to circumvent 2FA on their devices.
When the username's case is altered, this inappropriate authentication security weakness (ranked 9.8/10 in severity) in FortiGate SSL VPN enables attackers to log in to unpatched firewalls without being asked for the second element of authentication (FortiToken).
Fortinet alerted clients last week that attackers are still taking advantag...

