CVE-2026-8173
Received Received - Intake

Information Disclosure in Murrelektronik Xelity Switches

Vulnerability report for CVE-2026-8173, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: CERT VDE

Description

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
murrelektronik xelity From 2.1.0 (inc) to 2.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-8173 is an information disclosure vulnerability in Murrelektronik Xelity switches. When an authenticated admin uses the 'Copy learned MAC Addresses' function in the web GUI, the system logs MAC addresses from the device's MAC address table into a server-side log. Due to improper error handling, an unauthenticated attacker with network access can retrieve these logged MAC addresses using browser developer tools.

Detection Guidance

Check if the web interface of the Murrelektronik Xelity switch is accessible from the network. Inspect browser developer tools for logged MAC addresses in server responses after accessing the 'Copy learned MAC Addresses' function.

Impact Analysis

This vulnerability allows attackers to gather MAC addresses from network devices. These addresses can be used for network reconnaissance to map the network structure, enable MAC spoofing attacks to impersonate devices, or correlate network assets with physical devices for targeted attacks.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing MAC addresses, which may be considered personal data under GDPR if linked to individuals. Unauthorized access to network device logs may violate data protection requirements for safeguarding sensitive information.

Mitigation Strategies

Update the switch firmware to version 2.1.1 or later. Restrict web interface access to trusted networks only. Restart the switch to clear any exposed MAC address logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8173. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart