<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:00:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-360183</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-360183</link>
      <description>EUVD-2026-360183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-360183</guid>
    </item>
    <item>
      <title>fkie_cve-2026-8173</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-8173</link>
      <description>&lt;p&gt;The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the &amp;#39;Copy learned MAC Addresses&amp;#39; function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the &amp;#39;Copy learned MAC Addresses&amp;#39; function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-8173</guid>
    </item>
    <item>
      <title>GHSA-f42v-6cfh-6pj5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f42v-6cfh-6pj5</link>
      <description>&lt;p&gt;The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the &amp;#39;Copy learned MAC Addresses&amp;#39; function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the &amp;#39;Copy learned MAC Addresses&amp;#39; function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f42v-6cfh-6pj5</guid>
    </item>
    <item>
      <title>VDE-2026-061 — Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-061</link>
      <description>&lt;p&gt;An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device&amp;#39;s MAC address table to be written into a server-side log that is exposed via the device&amp;#39;s web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the &amp;#39;Copy learned MAC Addresses&amp;#39; function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device&amp;#39;s MAC address table to be written into a server-side log that is exposed via the device&amp;#39;s web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the &amp;#39;Copy learned MAC Addresses&amp;#39; function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-061</guid>
    </item>
  </channel>
</rss>
