CyberRota Analysis
AI-GeneratedThe web GUI of certain Murrelektronik Xelity switches is vulnerable due to improper error message handling, allowing unauthenticated attackers with network access to extract logged MAC addresses using browser developer tools. This exposure can lead to unauthorized network reconnaissance, potentially facilitating further attacks. Organizations using these switches should prioritize remediation to protect against potential exploitation.
Original NVD Description
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.