# Critical RADIUS Flaw in Schneider Electric Switches Could Enable Authentication Bypass Across Industrial Networks
## The Threat
Schneider Electric has disclosed a critical vulnerability in its Modicon family of industrial network switches that could allow attackers to forge RADIUS authentication responses and bypass network access controls across critical infrastructure globally. The flaw, tracked as CVE-2024-3596, stems from improper enforcement of message integrity checks in the RADIUS (Remote Authentication Dial-In User Service) protocol—a foundational security mechanism used by countless organizations to manage network authentication across energy systems, water treatment facilities, transportation networks, and other critical infrastructure.
The vulnerability exists in the Modicon Managed Switch product line and related variants, which serve as central network connectivity hubs for industrial environments. These switches handle authentication for devices accessing sensitive operational networks. Under specific configuration conditions, an unauthenticated attacker with network access to the switch could craft malicious RADIUS responses that bypass authentication entirely, impersonate authorized users, or force denial of service by converting valid access-accept responses into access-reject messages. An attacker with this capability essentially gains the ability to rewrite authentication decisions in real-time—a fundamental break in network trust.
The threat is particularly acute because RADIUS remains the dominant authentication protocol in enterprise industrial control system (ICS) and operational technology (OT) networks. Organizations relying on Schneider Electric switches for security-critical network segmentation between business and operational technology networks face significant exposure if they have disabled the RADIUS Message Authenticator option, which is why Schneider Electric's mitigation focuses on ensuring this protection remains enabled at all times.
## Severity and Impact
| Metric | Details |
|--------|---------|
| CVE Identifier | CVE-2024-3596 |
| CVSS v3.1 Base Score | 9.0 (CRITICAL) |
| CVSS Vector String | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Attack Complexity | High |
| Privileges Required | None |
| User Interaction | None |
| Scope | Changed |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| CWE | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel |
The CRITICAL severity rating reflects the potential for widespread impact across networked infrastructure. The attack changes scope (affects resources beyond the targeted switch itself), compromises confidentiality and integrity simultaneously, and creates denial-of-service conditions. While the attack complexity is rated as high—suggesting the attacker must have some knowledge of network topology or timing—the fact that no authentication is required and no user interaction is needed means a determined adversary positioned on the network could execute this attack.
## Affected Products
Schneider Electric Modicon Network Managed Switches are affected across all versions of three product families:
The vulnerability affects devices deployed worldwide across critical infrastructure sectors including energy utilities, water and wastewater systems, government facilities, commercial infrastructure, food and agriculture systems, and transportation networks.
## Mitigations
The default configuration of Schneider Electric Modicon switches is NOT vulnerable. The RADIUS Server Message Authenticator option is enabled by default, which prevents the attack.
Organizations should immediately verify that the RADIUS Server Message Authenticator parameter remains enabled in their Modicon switch deployments. This setting must be confirmed for all affected product families:
Connexium Managed Switches (TCSESM*):
radius server msgauthhmAgentRadiusServerMsgAuthModicon Managed Switches (MCSESM*, MCSESP*):
radius server auth modify msgauthhm2AgentRadiusServerMsgAuthModicon Redundancy Switches (MCSESR*):
radius server auth modify msgauthhm2AgentRadiusServerMsgAuthOrganizations should conduct a configuration audit across all Modicon switches in their network. Any instances where the Message Authenticator has been disabled—typically done by administrators to work around perceived performance issues or configuration conflicts—must be re-enabled immediately. Configuration changes should be documented and tested in a controlled environment before deployment to production critical infrastructure.
Additionally, Schneider Electric recommends industry best practices for defending industrial control systems:
## References
---
## HackWire Analysis
This vulnerability exemplifies a persistent challenge in industrial cybersecurity: the tension between security defaults and real-world operational troubleshooting. While Schneider Electric's decision to ship with message authentication enabled by default is correct, the existence of organizations that have disabled it reveals a critical pattern—administrators disabling security controls to resolve perceived compatibility issues, often without understanding the downstream implications.
The RADIUS protocol vulnerability is not new conceptually, but its presence in network infrastructure that guards access to power grids, water treatment systems, and transportation networks elevates its significance. Unlike a desktop vulnerability that affects individual users, a compromised RADIUS server or man-in-the-middle attack on RADIUS traffic in an industrial setting could enable an attacker to grant themselves access to operational networks where they can modify setpoints, disable alarms, or disrupt service delivery affecting thousands of people.
The attack complexity rating (high) is important context here—this is not a trivial exploit. An attacker must understand network timing, possess network positioning, and craft valid-looking RADIUS protocol responses. However, "high complexity" in the CVE world still means determined adversaries with moderate technical skill can execute this. Given the critical nature of the affected infrastructure and the fact that these switches have been deployed worldwide across decades, organizations should assume this vulnerability will eventually be weaponized if it hasn't been already.
The most actionable question for defenders: have we disabled RADIUS message authentication in our environment? Organizations that can answer "no" are protected. Those that cannot immediately confirm the answer should treat this as a fire drill—audit Modicon switch configurations across the entire network today, not this quarter. The barriers to entry for RADIUS protocol attacks are lower than other industrial vulnerabilities, and the reward (network access to critical infrastructure) is extraordinarily high.
— HackWire Editorial
## Related Coverage