Executive brief
The Danelec MacGregor Voyage Data Recorder (VDR), a device used on maritime vessels to record data for accident investigation, contains a vulnerability where authenticated users can download system backups. These backups contain sensitive account information and password hashes. If exploited, an attacker with low-level access could obtain credentials to gain full administrative control over the device, potentially compromising the integrity of recorded voyage data.
Technical details
The Danelec MacGregor Voyage Data Recorder (VDR) G4e suffers from an insufficiently protected credentials vulnerability (CWE-522). An authenticated user with low privileges can trigger a backup download of the device. This backup file contains sensitive configuration data, including user account details and password hashes. Because the attack requires adjacent network access and specific timing or configuration conditions (reflected in the High Attack Complexity), the CVSS score is moderated. Successful exploitation allows an attacker to perform offline brute-force attacks on the hashes to escalate privileges to an administrator level. The vulnerability is resolved in firmware version V5.250.
Affected products
- Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250
Timeline
- 2026-05-28: advisory: CISA ICS Advisory ICSA-26-148-01 published
- 2026-05-29: disclosed: CVE-2026-42951 published to NVD