<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_murrelektronikgmbh/10</id>
  <title>Most recent entries from csaf_murrelektronikgmbh</title>
  <updated>2026-10-02T09:12:26.607023+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-091</id>
    <title>VDE-2025-091 — Murrelektronik: Cleartext Transmission of Sensitive Information in IMPACT67 Pro</title>
    <updated>2025-10-14T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8
transmits login credentials over unencrypted HTTP using a GET request. The device does
not offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-091"/>
    <published>2025-10-14T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-062</id>
    <title>VDE-2026-062 — Several Murrelektronik Devices use Default SNMP Community Names</title>
    <updated>2026-07-14T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Several Murrelektronik devices using Profinet are shipped with the default SNMP community names ('public' for read access and 'private' for write access). If these community strings remain unchanged in the field, an unauthenticated attacker with network access to the device can read its configuration and, depending on the writable OIDs, modify device settings.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-062"/>
    <published>2026-07-14T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-063</id>
    <title>VDE-2026-063 — Murrelektronik Devices Vulnerable to SNMP GETBULK Reflection DDoS</title>
    <updated>2026-07-14T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple Murrelektronik network-enabled devices respond to SNMPv2c 'GETBULK' requests with disproportionately large response packets when the requesting party specifies a large max-repetitions value. This response amplification allows the affected devices to be misused as reflectors in distributed denial-of-service (DDoS) attacks against arbitrary third-party victims on the internet.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-063"/>
    <published>2026-07-14T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-061</id>
    <title>VDE-2026-061 — Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches</title>
    <updated>2026-08-25T09:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device's MAC address table to be written into a server-side log that is exposed via the device's web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the 'Copy learned MAC Addresses' function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-061"/>
    <published>2026-08-24T07:00:00+00:00</published>
  </entry>
</feed>
