The dangerous part is the trust check around RADIUS, not the switch hardware itself. If the Message Authenticator is disabled, a local attacker can tamper with an authentication reply in transit and turn a deny into an allow, or the other way around.
CISA says the issue affects all versions of Schneider Electric Connexium Managed Switches, Modicon Managed Switches, and Modicon Redundancy Switches, tied to CVE-2024-3596. Schneider says the default RADIUS configuration is not vulnerable; the risk appears when the RADIUS Server Message Authenticator option has been disabled.
For OT and industrial networks, that means patch status alone is not the whole question. A switch that accepts altered RADIUS replies can disrupt access or weaken the confidentiality and integrity of the devices behind it.