CVE-2024-3596
CVSS 9 CRITICAL: rADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid… EPSS 15% (96º percentile).
Vulnerabilità ed exploit
La parte pericolosa è il controllo di fiducia attorno a RADIUS, non l'hardware dello switch in sé. Se il Message Authenticator è disabilitato, un attaccante locale può alterare una risposta di autenticazione in transito e trasformare un deny in un allow, o viceversa.
1 fonte · 9 giu
CVSS 9 CRITICAL: rADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid… EPSS 15% (96º percentile).
CISA Advisories
Schneider Electric Modicon Network Managed Switches | CISA
Schneider Electric Modicon Network Managed Switches Summary Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product.
originalePart of the PlainSec briefing for 2026-06-09
Every edition of this story: L'integrità delle risposte RADIUS può ribaltare l'accesso allo switch