PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8173 Murrelektronik CVE debrief

An AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-24T07:16:54.570Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects Murrelektronik Xelity switches, potentially allowing information disclosure via the web interface. Organizations should review their inventory for exposure, restrict web interface access, and monitor logs for suspicious activity. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The web GUI logs MAC addresses when an authenticated administrator uses the 'Copy learned MAC Addresses' function, and due to improper error message generation, an unauthenticated attacker can retrieve these MAC addresses via browser developer tools.

Vendor
Murrelektronik
Product
Xelity 4TX M GE
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-24
Original CVE updated
2026-09-03
Advisory published
2026-08-24
Advisory updated
2026-09-03

Who should care

Organizations using Murrelektronik Xelity switches, particularly those with exposed web interfaces or high-risk network segments, should review and verify their inventory for potential exposure. Security teams and administrators responsible for network and device management should prioritize verification of affected devices and implement compensating controls to detect and respond to potential MAC address enumeration attempts. Vulnerability management and security operations teams should also be aware of the potential impact on their environments and plan accordingly. Additionally, operators and platform administrators may need to review and update their security configurations to mitigate potential risks associated with this vulnerability. This issue may impact security teams responsible for monitoring and incident response, as well as asset inventory management and vulnerability management processes. Security teams should also consider the potential operational impact and review context to ensure adequate defensive measures are in place. Security operations and incident response teams may need to review logs and monitor for suspicious activity related to this vulnerability. Asset management and vulnerability management teams should prioritize verification of affected devices and ensure that compensating controls are in place while remediation is scheduled and verified. Security teams should also review and verify their incident response plans to ensure they are prepared to respond to potential exploitation attempts. Security teams may need to review and update their security policies and procedures to ensure they are aligned with the potential risks associated with this vulnerability. Security teams should also consider the potential impact on their security posture and review their security controls to ensure they are adequate to mitigate potential risks associated with this vulnerability. Security teams should review and verify their security configurations to ensure they are aligned with the potential risks associated with this vulnerability. Security teams should also review and verify their vulnerability management processes to ensure they are adequate to

Technical summary

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools. This issue may allow for potential information disclosure, emphasizing the need for restricted access to the web interface and monitoring of web interface logs.

Defensive priority

Medium-priority defensive review recommended due to potential information disclosure via web interface.

Recommended defensive actions

  • Review and verify inventory of Murrelektronik Xelity switches for potential exposure
  • Restrict access to web interface of affected devices to authenticated administrators
  • Monitor web interface logs for suspicious activity
  • Implement compensating controls to detect and respond to potential MAC address enumeration attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence from official CVE and NVD sources indicates potential information disclosure via web interface of affected Murrelektronik Xelity switches. Limited detail available on affected products and versions. Further review of vendor documentation and security advisories is recommended to verify affected scope and severity. Defenders should verify inventory and exposure of Murrelektronik Xelity switches in their environments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8173 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8173

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8173 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8173

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.