Ten thousand firewalls are vulnerable to old vulnerability
Bleeping Computer reports that hackers are exploiting an old vulnerability in FortiOS that can be used to get around the two-factor authentication (2FA) requirement.
The vulnerability, designated CVE-2020-12812, was patched back in July 2020, but five and a half years later, there are still at least 10,000 firewalls that have not been updated.
To be on the safe side, all users of FortiOS and Fortigate are therefore urged to install the latest updates as soon as possible.
This news brief originally appeared on ComputerSweden .
More Fortinet security news:
FortiGate firewall credentials being stolen after vulnerabilities discovered
Fortinet criticized for ‘silent’ patching after disclosing second zero-day vulnerability in same equipment
Fortinet admins urged to update software to close FortiCloud SSO holes
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
