A critical flaw in Schneider Electric's industrial network switches can let an attacker manipulate authentication traffic, with no patch available yet.
The vulnerability, CVE-2024-3596, scores 9.0 on the CVSS scale and affects all versions of three Schneider Electric switch families: Connexium Managed Switches, Modicon Managed Switches, and Modicon Redundancy Switches. The flaw sits in the RADIUS authentication protocol — specifically in how message integrity is enforced. An attacker who can intercept RADIUS traffic could forge server responses, flipping an Access-Reject into an Access-Accept, or triggering a denial-of-service. These switches are deployed across critical infrastructure sectors including energy, water, transportation, and food production, worldwide.
The buried good news: the default configuration is not vulnerable. The risk only opens up if an administrator has explicitly disabled the RADIUS Server Message Authenticator option — a setting that exists in both CLI and SNMP management interfaces. That narrows the exposure, but it does not close it; any shop that disabled the option for compatibility reasons, or inherited a configuration without auditing it, is at risk right now. There is no firmware patch — the only fix is confirming the authenticator option is enabled.
CVE-2024-3596 is not new to the wider security community; it was disclosed in 2024 and affects the RADIUS protocol broadly, not just Schneider hardware. The delayed advisory for this specific product line is a familiar pattern in industrial control system security: ICS vendors often lag general-purpose IT vendors by months or years in acknowledging that a known protocol vulnerability applies to their equipment.
