Database/Control plane, storage & DevOps
Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.g
Impact
A logic flaw lets a user who changes their login case (e.g. 'User' vs 'user') complete SSL-VPN authentication without ever being prompted for their second factor — a clean bypass of FortiToken MFA on the VPN gateway. Confirmed in CISA's KEV catalog as actively exploited; if this FortiGate is the VPN entry point into a cluster's management network, MFA was supposed to be the thing stopping a stolen password from being enough.
Who can reach it
Requires a valid username/password (e.g. phished or reused) but no second factor — the attacker just varies the case of the username at login to skip the FortiToken prompt.
What to do
Firmware upgrade to the fixed FortiOS release per Fortinet PSIRT FG-IR-19-283. Given confirmed active exploitation, patch ahead of routine cycles, and afterward force a credential rotation for any accounts that authenticated to SSL-VPN during the vulnerable window in case MFA was bypassed on them already.
References
Related entries
- Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remoteCVE-2020-15373 · Brocade Fabric OS REST APICritical
- Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same consoleCVE-2020-15639 · Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management)Critical
- Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem duringCVE-2020-36770 · Slurm (Gentoo ebuild pkg_postinst)Critical
- Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as rootCVE-2021-1361 · Cisco Nexus 3000/9000 (internal file management service)Critical
- GitLab: unauthenticated SSRF through webhooks reaches the internal networkCVE-2021-22175 · GitLab (webhook request handling)Critical
- Brocade Fabric OS (hard-coded credentials): Documented hard-coded credentials in Brocade Fabric OSCVE-2021-27797 · Brocade Fabric OS (hard-coded credentials)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.