# Critical RADIUS Flaw in Schneider Electric Switches Could Enable Authentication Bypass Across Industrial Networks


## The Threat


Schneider Electric has disclosed a critical vulnerability in its Modicon family of industrial network switches that could allow attackers to forge RADIUS authentication responses and bypass network access controls across critical infrastructure globally. The flaw, tracked as CVE-2024-3596, stems from improper enforcement of message integrity checks in the RADIUS (Remote Authentication Dial-In User Service) protocol—a foundational security mechanism used by countless organizations to manage network authentication across energy systems, water treatment facilities, transportation networks, and other critical infrastructure.


The vulnerability exists in the Modicon Managed Switch product line and related variants, which serve as central network connectivity hubs for industrial environments. These switches handle authentication for devices accessing sensitive operational networks. Under specific configuration conditions, an unauthenticated attacker with network access to the switch could craft malicious RADIUS responses that bypass authentication entirely, impersonate authorized users, or force denial of service by converting valid access-accept responses into access-reject messages. An attacker with this capability essentially gains the ability to rewrite authentication decisions in real-time—a fundamental break in network trust.


The threat is particularly acute because RADIUS remains the dominant authentication protocol in enterprise industrial control system (ICS) and operational technology (OT) networks. Organizations relying on Schneider Electric switches for security-critical network segmentation between business and operational technology networks face significant exposure if they have disabled the RADIUS Message Authenticator option, which is why Schneider Electric's mitigation focuses on ensuring this protection remains enabled at all times.


## Severity and Impact


| Metric | Details |

|--------|---------|

| CVE Identifier | CVE-2024-3596 |

| CVSS v3.1 Base Score | 9.0 (CRITICAL) |

| CVSS Vector String | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |

| Attack Vector | Network |

| Attack Complexity | High |

| Privileges Required | None |

| User Interaction | None |

| Scope | Changed |

| Confidentiality Impact | High |

| Integrity Impact | High |

| Availability Impact | High |

| CWE | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel |


The CRITICAL severity rating reflects the potential for widespread impact across networked infrastructure. The attack changes scope (affects resources beyond the targeted switch itself), compromises confidentiality and integrity simultaneously, and creates denial-of-service conditions. While the attack complexity is rated as high—suggesting the attacker must have some knowledge of network topology or timing—the fact that no authentication is required and no user interaction is needed means a determined adversary positioned on the network could execute this attack.


## Affected Products


Schneider Electric Modicon Network Managed Switches are affected across all versions of three product families:


  • Connexium Managed Switches — All versions
  • Modicon Managed Switches — All versions
  • Modicon Redundancy Switches — All versions

  • The vulnerability affects devices deployed worldwide across critical infrastructure sectors including energy utilities, water and wastewater systems, government facilities, commercial infrastructure, food and agriculture systems, and transportation networks.


    ## Mitigations


    The default configuration of Schneider Electric Modicon switches is NOT vulnerable. The RADIUS Server Message Authenticator option is enabled by default, which prevents the attack.


    Organizations should immediately verify that the RADIUS Server Message Authenticator parameter remains enabled in their Modicon switch deployments. This setting must be confirmed for all affected product families:


    Connexium Managed Switches (TCSESM*):

  • CLI command: radius server msgauth
  • SNMP MIB: hmAgentRadiusServerMsgAuth

  • Modicon Managed Switches (MCSESM*, MCSESP*):

  • CLI command: radius server auth modify msgauth
  • SNMP MIB: hm2AgentRadiusServerMsgAuth

  • Modicon Redundancy Switches (MCSESR*):

  • CLI command: radius server auth modify msgauth
  • SNMP MIB: hm2AgentRadiusServerMsgAuth

  • Organizations should conduct a configuration audit across all Modicon switches in their network. Any instances where the Message Authenticator has been disabled—typically done by administrators to work around perceived performance issues or configuration conflicts—must be re-enabled immediately. Configuration changes should be documented and tested in a controlled environment before deployment to production critical infrastructure.


    Additionally, Schneider Electric recommends industry best practices for defending industrial control systems:


  • Isolate control and safety system networks behind firewalls from business networks
  • Implement physical access controls preventing unauthorized access to switches and infrastructure
  • Keep all controllers in locked cabinets and never leave them in "Program" mode
  • Scan all removable media (USB drives, external drives) before connecting to isolated networks
  • Never connect programming or management software to any network except its intended target network
  • Monitor RADIUS authentication logs for suspicious accept-to-reject conversions or unusual response patterns

  • ## References


  • [CVE-2024-3596 Full Record](https://www.cve.org/CVERecord?id=CVE-2024-3596)
  • Schneider Electric Security Advisories
  • CISA (Cybersecurity and Infrastructure Security Agency) Alerts
  • CWE-924: Improper Enforcement of Message Integrity During Transmission

  • ---


    ## HackWire Analysis


    This vulnerability exemplifies a persistent challenge in industrial cybersecurity: the tension between security defaults and real-world operational troubleshooting. While Schneider Electric's decision to ship with message authentication enabled by default is correct, the existence of organizations that have disabled it reveals a critical pattern—administrators disabling security controls to resolve perceived compatibility issues, often without understanding the downstream implications.


    The RADIUS protocol vulnerability is not new conceptually, but its presence in network infrastructure that guards access to power grids, water treatment systems, and transportation networks elevates its significance. Unlike a desktop vulnerability that affects individual users, a compromised RADIUS server or man-in-the-middle attack on RADIUS traffic in an industrial setting could enable an attacker to grant themselves access to operational networks where they can modify setpoints, disable alarms, or disrupt service delivery affecting thousands of people.


    The attack complexity rating (high) is important context here—this is not a trivial exploit. An attacker must understand network timing, possess network positioning, and craft valid-looking RADIUS protocol responses. However, "high complexity" in the CVE world still means determined adversaries with moderate technical skill can execute this. Given the critical nature of the affected infrastructure and the fact that these switches have been deployed worldwide across decades, organizations should assume this vulnerability will eventually be weaponized if it hasn't been already.


    The most actionable question for defenders: have we disabled RADIUS message authentication in our environment? Organizations that can answer "no" are protected. Those that cannot immediately confirm the answer should treat this as a fire drill—audit Modicon switch configurations across the entire network today, not this quarter. The barriers to entry for RADIUS protocol attacks are lower than other industrial vulnerabilities, and the reward (network access to critical infrastructure) is extraordinarily high.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Critical Infrastructure](https://www.hackwire.news/category/critical-infrastructure) and [Network Security](https://www.hackwire.news/category/network-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)