Description
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The flaw exists in the web GUI of certain Murrelektronik Xelity switches. When an authenticated administrator uses the "Copy learned MAC Addresses" feature, the system logs the MAC addresses in its internal table. Due to improper error handling, an unauthenticated attacker with network reach to the GUI can view those logs through browser developer tools. This permits leakage of MAC addresses from the switch, which can aid network mapping and reconnaissance activities. The underlying weakness is classified as CWE‑209 – Information Exposure Through Error Messages.

Affected Systems

The affected line of products includes a range of Murrelektronik Xelity switches, such as Xelity 10 TX IP67 M FE, Xelity 8 TX M GE, Xelity 6 TX M GE, and others enumerated in the vendor list. All devices running firmware version V2.1.0 are potentially vulnerable, as the firmware identifier appears in the CPE strings. No other version or vendor information was supplied.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate impact. The EPSS score is unavailable, but the attacker only needs unauthenticated network access to the web interface, a readily achievable condition in most environments. The vulnerability is not listed in the CISA KEV catalog. Because the exposed data is logged MAC addresses, the risk is primarily in providing an attacker with additional network intelligence. Exploitation would involve a trivial action of accessing the admin interface via a browser, then inspecting logged data through developer tools. No special privileges or advanced capabilities are required beyond network reach.

Generated by OpenCVE AI on August 24, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify if a firmware update that fixes this issue has been released and upgrade the switches if possible.
  • Restrict access to the web‑based management console to trusted management networks, VPNs, or dedicated secure VLANs so that only authorized personnel can reach it.
  • If an immediate patch is unavailable, disable or remove the "Copy learned MAC Addresses" function in the GUI to stop storing the addresses in the log.

Generated by OpenCVE AI on August 24, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Murrelektronik 6 Tx M Ge + 4 Power M12 Ip67
Murrelektronik xelity-16tx-m-ge
Murrelektronik xelity-16tx-m-ge-pn
Murrelektronik xelity 10 Tx Ip67 M Fe 4p
Murrelektronik xelity 10 Tx Ip67 M Fe 5p
Murrelektronik xelity 10 Tx Ip67 M Fe Pn 4p
Murrelektronik xelity 10 Tx Ip67 M Fe Pn 5p
Murrelektronik xelity 10 Tx Ip67 M Ge 4p
Murrelektronik xelity 10 Tx Ip67 M Ge 5p
Murrelektronik xelity 10 Tx Ip67 M Ge Pn 4p
Murrelektronik xelity 10 Tx Ip67 M Ge Pn 5p
Murrelektronik xelity 4tx M Ge
Murrelektronik xelity 4tx M Ge Pn
Murrelektronik xelity 6tx 4pw Ip67 M Ge Pn 4p
Murrelektronik xelity 6tx 4pw Ip67 M Ge Pn 5p
Murrelektronik xelity 6tx M Ge
Murrelektronik xelity 6tx M Ge Pn
Murrelektronik xelity 8 +2 Tx Ip67 M Ge 4p
Murrelektronik xelity 8 +2 Tx Ip67 M Ge 5p
Murrelektronik xelity 8 +2 Tx Ip67 M Ge Pn 4p
Murrelektronik xelity 8 +2 Tx Ip67 M Ge Pn 5p
Murrelektronik xelity 8tx M Ge
Murrelektronik xelity 8tx M Ge Pn
Vendors & Products Murrelektronik 6 Tx M Ge + 4 Power M12 Ip67
Murrelektronik xelity-16tx-m-ge
Murrelektronik xelity-16tx-m-ge-pn
Murrelektronik xelity 10 Tx Ip67 M Fe 4p
Murrelektronik xelity 10 Tx Ip67 M Fe 5p
Murrelektronik xelity 10 Tx Ip67 M Fe Pn 4p
Murrelektronik xelity 10 Tx Ip67 M Fe Pn 5p
Murrelektronik xelity 10 Tx Ip67 M Ge 4p
Murrelektronik xelity 10 Tx Ip67 M Ge 5p
Murrelektronik xelity 10 Tx Ip67 M Ge Pn 4p
Murrelektronik xelity 10 Tx Ip67 M Ge Pn 5p
Murrelektronik xelity 4tx M Ge
Murrelektronik xelity 4tx M Ge Pn
Murrelektronik xelity 6tx 4pw Ip67 M Ge Pn 4p
Murrelektronik xelity 6tx 4pw Ip67 M Ge Pn 5p
Murrelektronik xelity 6tx M Ge
Murrelektronik xelity 6tx M Ge Pn
Murrelektronik xelity 8 +2 Tx Ip67 M Ge 4p
Murrelektronik xelity 8 +2 Tx Ip67 M Ge 5p
Murrelektronik xelity 8 +2 Tx Ip67 M Ge Pn 4p
Murrelektronik xelity 8 +2 Tx Ip67 M Ge Pn 5p
Murrelektronik xelity 8tx M Ge
Murrelektronik xelity 8tx M Ge Pn

Mon, 24 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Description The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
Title Information Disclosure via 'Copy learned MAC Addresses' Function
First Time appeared Murrelektronik
Murrelektronik xelity Firmware
Weaknesses CWE-209
CPEs cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58820:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58821:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58822:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58823:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58824:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58825:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58826:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58827:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58840:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58841:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58842:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58843:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58844:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58845:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58847:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58850:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58851:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58852:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58853:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58854:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58855:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58857:*
cpe:2.3:o:murrelektronik:xelity_firmware:V2.1.0:*:*:*:*:*:58860:*
Vendors & Products Murrelektronik
Murrelektronik xelity Firmware
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Murrelektronik 6 Tx M Ge + 4 Power M12 Ip67 Xelity-16tx-m-ge Xelity-16tx-m-ge-pn Xelity 10 Tx Ip67 M Fe 4p Xelity 10 Tx Ip67 M Fe 5p Xelity 10 Tx Ip67 M Fe Pn 4p Xelity 10 Tx Ip67 M Fe Pn 5p Xelity 10 Tx Ip67 M Ge 4p Xelity 10 Tx Ip67 M Ge 5p Xelity 10 Tx Ip67 M Ge Pn 4p Xelity 10 Tx Ip67 M Ge Pn 5p Xelity 4tx M Ge Xelity 4tx M Ge Pn Xelity 6tx 4pw Ip67 M Ge Pn 4p Xelity 6tx 4pw Ip67 M Ge Pn 5p Xelity 6tx M Ge Xelity 6tx M Ge Pn Xelity 8 +2 Tx Ip67 M Ge 4p Xelity 8 +2 Tx Ip67 M Ge 5p Xelity 8 +2 Tx Ip67 M Ge Pn 4p Xelity 8 +2 Tx Ip67 M Ge Pn 5p Xelity 8tx M Ge Xelity 8tx M Ge Pn Xelity Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-27T16:46:11.517Z

Reserved: 2026-05-08T13:56:01.059Z

Link: CVE-2026-8173

cve-icon Vulnrichment

Updated: 2026-08-27T16:11:43.415Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T07:16:54.570

Modified: 2026-09-03T16:57:26.583

Link: CVE-2026-8173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:11:42Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information