Summary
An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.
Impact
An unauthenticated attacker with network access to the web interface of an affected Xelity switch can retrieve a list of MAC addresses learned by the device once the 'Copy learned MAC Addresses' function has been used at least once by an administrator (loss of confidentiality). The disclosed MAC addresses identify devices currently or recently active on the affected switch ports and may aid an attacker in reconnaissance of the OT network topology, in subsequent MAC spoofing attacks against port-security or 802.1X bypass mechanisms, or in correlating network assets to physical devices for targeted follow-on attacks.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| 58860 | 6 TX M GE + 4 Power M12 IP67 | Murrelektronik Firmware Xelity V2.1.0 |
| 58840 | Xelity 10 TX IP67 M FE 4P | Murrelektronik Firmware Xelity V2.1.0 |
| 58850 | Xelity 10 TX IP67 M FE 5P | Murrelektronik Firmware Xelity V2.1.0 |
| 58841 | Xelity 10 TX IP67 M FE PN 4P | Murrelektronik Firmware Xelity V2.1.0 |
| 58851 | Xelity 10 TX IP67 M FE PN 5P | Murrelektronik Firmware Xelity V2.1.0 |
| 58844 | Xelity 10 TX IP67 M GE 4P | Murrelektronik Firmware Xelity V2.1.0 |
| 58854 | Xelity 10 TX IP67 M GE 5P | Murrelektronik Firmware Xelity V2.1.0 |
| 58845 | Xelity 10 TX IP67 M GE PN 4P | Murrelektronik Firmware Xelity V2.1.0 |
| 58855 | Xelity 10 TX IP67 M GE PN 5P | Murrelektronik Firmware Xelity V2.1.0 |
| 58820 | Xelity 4TX M GE | Murrelektronik Firmware Xelity V2.1.0 |
| 58821 | Xelity 4TX M GE PN | Murrelektronik Firmware Xelity V2.1.0 |
| 58847 | Xelity 6TX 4PW IP67 M GE PN 4P | Murrelektronik Firmware Xelity V2.1.0 |
| 58857 | Xelity 6TX 4PW IP67 M GE PN 5P | Murrelektronik Firmware Xelity V2.1.0 |
| 58822 | Xelity 6TX M GE | Murrelektronik Firmware Xelity V2.1.0 |
| 58823 | Xelity 6TX M GE PN | Murrelektronik Firmware Xelity V2.1.0 |
| 58842 | Xelity 8 +2 TX IP67 M GE 4P | Murrelektronik Firmware Xelity V2.1.0 |
| 58852 | Xelity 8 +2 TX IP67 M GE 5P | Murrelektronik Firmware Xelity V2.1.0 |
| 58843 | Xelity 8 +2 TX IP67 M GE PN 4P | Murrelektronik Firmware Xelity V2.1.0 |
| 58853 | Xelity 8 +2 TX IP67 M GE PN 5P | Murrelektronik Firmware Xelity V2.1.0 |
| 58824 | Xelity 8TX M GE | Murrelektronik Firmware Xelity V2.1.0 |
| 58825 | Xelity 8TX M GE PN | Murrelektronik Firmware Xelity V2.1.0 |
| 58826 | Xelity-16TX-M-GE | Murrelektronik Firmware Xelity V2.1.0 |
| 58827 | Xelity-16TX-M-GE-PN | Murrelektronik Firmware Xelity V2.1.0 |
Vulnerabilities
Expand / Collapse allThe web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.
Mitigation
- Until the firmware update can be deployed, restart the affected Xelity switches after any administrator has used the 'Copy learned MAC Addresses' function in the web GUI. Restarting the device clears the log, removing the leaked MAC addresses from the web-accessible output. Alternatively, avoid using the 'Copy learned MAC Addresses' function on devices that have unauthenticated network exposure of their web interface.
- Restrict network access to the web management interface (TCP 80/443) of the affected Xelity switches to authorized management stations only, via firewall ACLs or by placing the switches in a dedicated management VLAN. This prevents unauthenticated attackers from reaching the web interface to retrieve the leaked log content.
Remediation
Update the affected Xelity switches to firmware version V2.1.1 or later. This firmware version removes the syslog error that caused the MAC address table contents to be written to a web-accessible log. (https://shop.murrelektronik.de/)
Acknowledgments
Murrelektronik GmbH thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 08/24/2026 09:00 | initial release |