news.mlab.sh
Back to the feed
vulnerability

Schneider Electric Modicon Network Managed Switches

High
Summary

Schneider Electric has identified a vulnerability (CVE-2024-3596) in its Modicon Network Managed Switches due to a misconfigured RADIUS protocol. Specifically, disabling the RADIUS Server Message Authenticator option makes the devices susceptible to forgery attacks, potentially leading to denial-of-service and data compromise. Schneider Electric recommends keeping this parameter enabled via CLI and SNMP to mitigate the risk.

This vulnerability, tracked as CVE-2024-3596, affects all versions of Schneider Electric’s Modicon Network Managed Switches, Connexium Managed Switches, and Modicon Redundancy Switches. The issue stems from a lack of proper enforcement of message integrity during transmission via the RADIUS protocol. If the RADIUS Server Message Authenticator option is disabled, an attacker could manipulate responses, potentially causing a denial-of-service or compromising the confidentiality and integrity of connected devices. The vulnerability impacts a wide range of critical infrastructure sectors, including commercial facilities, energy, food and agriculture, government services, transportation systems, and water and wastewater management. Schneider Electric has reported this vulnerability to CISA, and recommends immediate action to address the risk.

Read the full article at CISA Advisories