CVE-2024-3596
CVSS 9 CRITICAL: rADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid… EPSS 15% (96º percentile).
Vulnerabilità · 112 giorni fa
La parte pericolosa è il controllo di fiducia attorno a RADIUS, non l'hardware dello switch in sé. Se il Message Authenticator è disabilitato, un attaccante locale può alterare una risposta di autenticazione in transito e trasformare un deny in un allow, o viceversa.
CVSS 9 CRITICAL: rADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid… EPSS 15% (96º percentile).
1 fonte che coprono questa storia
Schneider Electric Modicon Network Managed Switches | CISA
Schneider Electric Modicon Network Managed Switches Summary Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product.
Part of the PlainSec briefing for 2026-06-09