The vendor explicitly identifies these products as affected by this CVE.
- RUGGEDCOM APE1808
- Summary
- An insufficient verification of data authenticity vulnerability [CWE-345] in FortiOS & FortiProxy SSL-VPN tunnel mode may allow an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.
- Remediation
- Update Fortigate NGFW to V7.4.3. Contact customer support to receive patch and update information.
