Sceawere

Vulnerability Detail

CVE-2026-8173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Murrelektronik Xelity MAC Address Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
Murrelektronik
Product
Xelity 4TX M GE
Attack Type
CWE-209 Generation of Error Message Containing Sensitive Information
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-24T07:16:54.570Z",
  "pubdate": "2026-08-24T07:16:54.570Z",
  "executiveSummary": "An information disclosure vulnerability affects the web GUI of Murrelektronik Xelity switches. The flaw involves the improper generation of error messages when an authenticated administrator interacts with the 'Copy learned MAC Addresses' function. Consequently, an unauthenticated attacker with direct network access to the web interface can successfully retrieve sensitive MAC addresses directly from the device's MAC address table by leveraging browser developer tools. This security deficiency exposes internal network topology and connected device identifiers without requiring valid credentials. The risk implications include reconnaissance activities that could facilitate subsequent targeted attacks against the underlying network infrastructure. Exploitation requires network reachability to the administrative web interface of the affected Murrelektronik Xelity switches, allowing unauthorized retrieval of operational data intended strictly for authenticated administrative personnel.",
  "technicalDetails": "The vulnerability resides within the web application interface of Murrelektronik Xelity switches, specifically tied to the handling and logging mechanisms of the 'Copy learned MAC Addresses' function. The root cause stems from improper generation and exposure of error messages by the underlying web server or application logic when processing specific requests or handling state transitions associated with the administrative copy function. In a standard operational workflow, this administrative feature captures active MAC addresses from the internal forwarding database or MAC address table. Due to inadequate error handling and insufficient output sanitization or access control enforcement at the presentation layer, error responses or debugging logs generated during this process inadvertently expose the populated MAC address data to unauthorized TCP/IP connections.\nThe attack flow proceeds as follows: An unauthenticated malicious actor establishes network connectivity to the HTTP or HTTPS management interface of the target Murrelektronik Xelity switch. By observing network traffic, sending crafted HTTP requests, or inspecting responses associated with the web GUI's execution paths—particularly interactions or triggers near the 'Copy learned MAC Addresses' function—the attacker forces or observes the generation of verbose error messages. The attacker then utilizes standard browser developer tools, such as the Network or Console panels, to inspect the HTTP response bodies, headers, or client-side application state where the improperly handled error messages serialize the internal MAC address table data. Because the application fails to restrict access to these error messages based on session authentication state, unauthenticated entities can read the sensitive payload directly from the browser interface.\nThe vulnerable component is the web GUI error generation and logging subsystem responsible for handling administrative features. The required privileges and authentication state for exploitation are strictly unauthenticated, as the flaw bypasses session validation checks implemented elsewhere in the application. Network exposure is localized to the management interface of the affected switches, typically accessible over local area networks or improperly segmented management VLANs. The post-exploitation impact is primarily informational, enabling the unauthorized extraction of hardware identifiers linked to devices connected to the switch ports. This facilitates reconnaissance and network mapping, providing attackers with actionable intelligence regarding active hosts within the administrative domain."
}
CVE-2026-8173: Murrelektronik Xelity MAC Address Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere