CVE-2026-8173
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.21%
- CWE
- CWE-209
- Published
- 2026-08-24
- Last modified
- 2026-08-27
Affected products
- Murrelektronik Xelity 4TX M GE
- Murrelektronik Xelity 4TX M GE PN
- Murrelektronik Xelity 6TX M GE
- Murrelektronik Xelity 6TX M GE PN
- Murrelektronik Xelity 8TX M GE
- Murrelektronik Xelity 8TX M GE PN
- Murrelektronik Xelity-16TX-M-GE
- Murrelektronik Xelity-16TX-M-GE-PN
Weakness type
Related vulnerabilities
- CVE-2026-66306 — Skype for Business Information Disclosure Vulnerability
- CVE-2026-69294 — Microsoft COM for Windows Information Disclosure Vulnerability
- CVE-2026-68886 — Windows Network Connection Broker Information Disclosure Vulnerability
- CVE-2026-67383 — Microsoft SQL Server Information Disclosure Vulnerability
- CVE-2026-69684 — Windows Error Reporting Information Disclosure Vulnerability
- CVE-2026-69552 — Windows Print Spooler Components Information Disclosure Vulnerability
- CVE-2026-11873 — Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure
- CVE-2026-82739 — Ash.Resource.Validation.Confirm leaks a confirmed field's stored value in the atomic mismatch error