CVE-2026-8173

MEDIUMCVSS 5.3/10EPSS 0.21%

Last modified

CVE-2026-8173 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS 4.0
5.3/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.21%

10.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
MurrelektronikXelity 4TX M GE2.1.0
MurrelektronikXelity 4TX M GE PN2.1.0
MurrelektronikXelity 6TX M GE2.1.0
MurrelektronikXelity 6TX M GE PN2.1.0
MurrelektronikXelity 8TX M GE2.1.0
MurrelektronikXelity 8TX M GE PN2.1.0
MurrelektronikXelity-16TX-M-GE2.1.0
MurrelektronikXelity-16TX-M-GE-PN2.1.0
MurrelektronikXelity 10 TX IP67 M FE 4P2.1.0
MurrelektronikXelity 10 TX IP67 M FE PN 4P2.1.0
MurrelektronikXelity 8 +2 TX IP67 M GE 4P2.1.0
MurrelektronikXelity 8 +2 TX IP67 M GE PN 4P2.1.0
MurrelektronikXelity 10 TX IP67 M GE 4P2.1.0
MurrelektronikXelity 10 TX IP67 M GE PN 4P2.1.0
MurrelektronikXelity 6TX 4PW IP67 M GE PN 4P2.1.0
MurrelektronikXelity 10 TX IP67 M FE 5P2.1.0
MurrelektronikXelity 10 TX IP67 M FE PN 5P2.1.0
MurrelektronikXelity 8 +2 TX IP67 M GE 5P2.1.0
MurrelektronikXelity 8 +2 TX IP67 M GE PN 5P2.1.0
MurrelektronikXelity 10 TX IP67 M GE 5P2.1.0
MurrelektronikXelity 10 TX IP67 M GE PN 5P2.1.0
MurrelektronikXelity 6TX 4PW IP67 M GE PN 5P2.1.0
Murrelektronik6 TX M GE + 4 Power M12 IP672.1.0

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-8173?
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
How severe is CVE-2026-8173?
CVE-2026-8173 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-8173?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-8173?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST