CVE-2024-3596
CVSS 9 CRITICAL: rADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid… EPSS 15% (96th percentile).
Vulnerabilities · 97 days ago
The dangerous part is the trust check around RADIUS, not the switch hardware itself. If the Message Authenticator is disabled, a local attacker can tamper with an authentication reply in transit and turn a deny into an allow, or the other way around.
CISA says the issue affects all versions of Schneider Electric Connexium Managed Switches, Modicon Managed Switches, and Modicon Redundancy Switches, tied to CVE-2024-3596. Schneider says the default RADIUS configuration is not vulnerable; the risk appears when the RADIUS Server Message Authenticator option has been disabled.
For OT and industrial networks, that means patch status alone is not the whole question. A switch that accepts altered RADIUS replies can disrupt access or weaken the confidentiality and integrity of the devices behind it.
CVSS 9 CRITICAL: rADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid… EPSS 15% (96th percentile).
1 source covering this story
Schneider Electric Modicon Network Managed Switches | CISA
Schneider Electric Modicon Network Managed Switches Summary Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product.
Part of the PlainSec briefing for 2026-06-09