An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/irinarenteria/attackerkb-clj
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/r0eXpeR/supplier
- https://github.com/soosmile/POC
- https://github.com/triw0lf/Security-Matters-22