<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_murrelektronikgmbh</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:11:55 +0000</lastBuildDate>
    <item>
      <title>VDE-2026-061 — Murrelektronik: Vulnerability in 'Copy learned MAC Addresses' function enables MAC Spoofing on Xelity Switches</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-061</link>
      <description>&lt;p&gt;An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device&amp;#39;s MAC address table to be written into a server-side log that is exposed via the device&amp;#39;s web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the &amp;#39;Copy learned MAC Addresses&amp;#39; function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An information disclosure vulnerability in the web GUI of Murrelektronik Xelity switches causes MAC addresses from the device&amp;#39;s MAC address table to be written into a server-side log that is exposed via the device&amp;#39;s web interface to unauthenticated users. The leak is triggered when an authenticated administrator invokes the &amp;#39;Copy learned MAC Addresses&amp;#39; function, which causes a syslog error that inserts the affected MAC addresses into the log output. Once the error has been triggered, any unauthenticated attacker with network access to the web interface can retrieve the leaked MAC addresses via common browser developer tools. The vulnerable functionality was introduced in version 2.1.0 and is fixed in version 2.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-061</guid>
      <pubDate>Mon, 24 Aug 2026 07:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-063 — Murrelektronik Devices Vulnerable to SNMP GETBULK Reflection DDoS</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-063</link>
      <description>&lt;p&gt;Multiple Murrelektronik network-enabled devices respond to SNMPv2c &amp;#39;GETBULK&amp;#39; requests with disproportionately large response packets when the requesting party specifies a large max-repetitions value. This response amplification allows the affected devices to be misused as reflectors in distributed denial-of-service (DDoS) attacks against arbitrary third-party victims on the internet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple Murrelektronik network-enabled devices respond to SNMPv2c &amp;#39;GETBULK&amp;#39; requests with disproportionately large response packets when the requesting party specifies a large max-repetitions value. This response amplification allows the affected devices to be misused as reflectors in distributed denial-of-service (DDoS) attacks against arbitrary third-party victims on the internet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-063</guid>
      <pubDate>Tue, 14 Jul 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2026-062 — Several Murrelektronik Devices use Default SNMP Community Names</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-062</link>
      <description>&lt;p&gt;Several Murrelektronik devices using Profinet are shipped with the default SNMP community names (&amp;#39;public&amp;#39; for read access and &amp;#39;private&amp;#39; for write access). If these community strings remain unchanged in the field, an unauthenticated attacker with network access to the device can read its configuration and, depending on the writable OIDs, modify device settings.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Several Murrelektronik devices using Profinet are shipped with the default SNMP community names (&amp;#39;public&amp;#39; for read access and &amp;#39;private&amp;#39; for write access). If these community strings remain unchanged in the field, an unauthenticated attacker with network access to the device can read its configuration and, depending on the writable OIDs, modify device settings.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-062</guid>
      <pubDate>Tue, 14 Jul 2026 10:00:00 +0000</pubDate>
    </item>
    <item>
      <title>VDE-2025-091 — Murrelektronik: Cleartext Transmission of Sensitive Information in IMPACT67 Pro</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-091</link>
      <description>&lt;p&gt;The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8
transmits login credentials over unencrypted HTTP using a GET request. The device does
not offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The embedded web interface of the MURRELEKTRONIK IMPACT67 Pro PN DIO8 IOL8
transmits login credentials over unencrypted HTTP using a GET request. The device does
not offer HTTPS/TLS support, exposing user credentials to passive interception by any attacker on the same network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-091</guid>
      <pubDate>Tue, 14 Oct 2025 10:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
