Zurück zur Übersicht

Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches

VDE-2026-061
Last update
24.08.2026 09:00
Published at
24.08.2026 09:00
Vendor(s)
Murrelektronik GmbH
External ID
VDE-2026-061
CSAF Document

Summary

An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.

Impact

An unauthenticated attacker with network access to the web interface of an affected Xelity switch can retrieve a list of MAC addresses learned by the device once the 'Copy learned MAC Addresses' function has been used at least once by an administrator (loss of confidentiality). The disclosed MAC addresses identify devices currently or recently active on the affected switch ports and may aid an attacker in reconnaissance of the OT network topology, in subsequent MAC spoofing attacks against port-security or 802.1X bypass mechanisms, or in correlating network assets to physical devices for targeted follow-on attacks.

Affected Product(s)

Model no. Product name Affected versions
58860 6 TX M GE + 4 Power M12 IP67 Murrelektronik Firmware Xelity V2.1.0
58840 Xelity 10 TX IP67 M FE 4P Murrelektronik Firmware Xelity V2.1.0
58850 Xelity 10 TX IP67 M FE 5P Murrelektronik Firmware Xelity V2.1.0
58841 Xelity 10 TX IP67 M FE PN 4P Murrelektronik Firmware Xelity V2.1.0
58851 Xelity 10 TX IP67 M FE PN 5P Murrelektronik Firmware Xelity V2.1.0
58844 Xelity 10 TX IP67 M GE 4P Murrelektronik Firmware Xelity V2.1.0
58854 Xelity 10 TX IP67 M GE 5P Murrelektronik Firmware Xelity V2.1.0
58845 Xelity 10 TX IP67 M GE PN 4P Murrelektronik Firmware Xelity V2.1.0
58855 Xelity 10 TX IP67 M GE PN 5P Murrelektronik Firmware Xelity V2.1.0
58820 Xelity 4TX M GE Murrelektronik Firmware Xelity V2.1.0
58821 Xelity 4TX M GE PN Murrelektronik Firmware Xelity V2.1.0
58847 Xelity 6TX 4PW IP67 M GE PN 4P Murrelektronik Firmware Xelity V2.1.0
58857 Xelity 6TX 4PW IP67 M GE PN 5P Murrelektronik Firmware Xelity V2.1.0
58822 Xelity 6TX M GE Murrelektronik Firmware Xelity V2.1.0
58823 Xelity 6TX M GE PN Murrelektronik Firmware Xelity V2.1.0
58842 Xelity 8 +2 TX IP67 M GE 4P Murrelektronik Firmware Xelity V2.1.0
58852 Xelity 8 +2 TX IP67 M GE 5P Murrelektronik Firmware Xelity V2.1.0
58843 Xelity 8 +2 TX IP67 M GE PN 4P Murrelektronik Firmware Xelity V2.1.0
58853 Xelity 8 +2 TX IP67 M GE PN 5P Murrelektronik Firmware Xelity V2.1.0
58824 Xelity 8TX M GE Murrelektronik Firmware Xelity V2.1.0
58825 Xelity 8TX M GE PN Murrelektronik Firmware Xelity V2.1.0
58826 Xelity-16TX-M-GE Murrelektronik Firmware Xelity V2.1.0
58827 Xelity-16TX-M-GE-PN Murrelektronik Firmware Xelity V2.1.0

Vulnerabilities

Expand / Collapse all

Published
24.08.2026 08:50
Weakness
Generation of Error Message Containing Sensitive Information (CWE-209)
Summary

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.

References

Mitigation

  • Until the firmware update can be deployed, restart the affected Xelity switches after any administrator has used the 'Copy learned MAC Addresses' function in the web GUI. Restarting the device clears the log, removing the leaked MAC addresses from the web-accessible output. Alternatively, avoid using the 'Copy learned MAC Addresses' function on devices that have unauthenticated network exposure of their web interface.
  • Restrict network access to the web management interface (TCP 80/443) of the affected Xelity switches to authorized management stations only, via firewall ACLs or by placing the switches in a dedicated management VLAN. This prevents unauthenticated attackers from reaching the web interface to retrieve the leaked log content.

Remediation

Update the affected Xelity switches to firmware version V2.1.1 or later. This firmware version removes the syslog error that caused the MAC address table contents to be written to a web-accessible log. (https://shop.murrelektronik.de/)

Acknowledgments

Murrelektronik GmbH thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 24.08.2026 09:00 initial release