Impact
The flaw exists in the web GUI of certain Murrelektronik Xelity switches. When an authenticated administrator uses the "Copy learned MAC Addresses" feature, the system logs the MAC addresses in its internal table. Due to improper error handling, an unauthenticated attacker with network reach to the GUI can view those logs through browser developer tools. This permits leakage of MAC addresses from the switch, which can aid network mapping and reconnaissance activities. The underlying weakness is classified as CWE‑209 – Information Exposure Through Error Messages.
Affected Systems
The affected line of products includes a range of Murrelektronik Xelity switches, such as Xelity 10 TX IP67 M FE, Xelity 8 TX M GE, Xelity 6 TX M GE, and others enumerated in the vendor list. All devices running firmware version V2.1.0 are potentially vulnerable, as the firmware identifier appears in the CPE strings. No other version or vendor information was supplied.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate impact. The EPSS score is unavailable, but the attacker only needs unauthenticated network access to the web interface, a readily achievable condition in most environments. The vulnerability is not listed in the CISA KEV catalog. Because the exposed data is logged MAC addresses, the risk is primarily in providing an attacker with additional network intelligence. Exploitation would involve a trivial action of accessing the admin interface via a browser, then inspecting logged data through developer tools. No special privileges or advanced capabilities are required beyond network reach.
OpenCVE Enrichment