CVE-2026-8173: Information Disclosure via 'Copy learned MAC Addresses' Function
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
Affected Software
Event History
Frequently Asked Questions
What must happen before MAC addresses can be exposed?
An authenticated administrator must use the web GUI's "Copy learned MAC Addresses" function, which causes MAC addresses from the device's MAC address table to be logged.
Who can retrieve the exposed information?
An unauthenticated attacker with network access to the switch web interface can retrieve the logged MAC addresses through browser developer tools. No attacker authentication or user interaction is required.
What information is disclosed?
The issue exposes MAC addresses recorded in the switch's MAC address table. The provided information does not indicate disclosure of configuration data, credentials, or other device information.