CISA

Schneider Electric Modicon Network Managed Switches

From Cybersecurity and Infrastructure Security Agency ↗

Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed Switch product. The Modicon Network Managed Switch product provides connectivity for multiple Ethernet devices, network management, enhanced cyber security and more advanced switching features. Failure to apply the mitigation provided below may risk forgery attacks in RADIUS Protocol, which could result in modification of any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response which could result in the possibility of denial of service and loss of confidentiality, integrity of the devices connected to the switch.

The following versions of Schneider Electric Modicon Network Managed Switches are affected:

Connexium Managed Switches vers:all/* 

Modicon Managed Switches vers:all/* 

Modicon Redundancy Switches vers:all/* 

Vendor

Equipment

Schneider...