Executive brief
The Danelec MacGregor Voyage Data Recorder (VDR), which functions as a 'black box' for maritime vessels, uses an insecure method for storing user passwords. This flaw allows an attacker with access to the ship's local network to potentially crack user passwords through automated guessing. If successful, an attacker could gain unauthorized access to the device, compromising the integrity of recorded voyage data.
Technical details
The vulnerability (CWE-916) exists in the password storage mechanism of the MacGregor VDR G4e. The device utilizes a hashing algorithm that imposes a maximum password length and lacks sufficient computational complexity, making it susceptible to offline brute-force or dictionary attacks. An attacker who has already obtained password hashes (e.g., via CVE-2026-42951) and has adjacent network access can exploit this to recover plaintext credentials. This issue is resolved in firmware version V5.250.
Affected products
- Danelec MacGregor Voyage Data Recorder (VDR) G4e < V5.250
Timeline
- 2026-05-28: advisory: CISA ICSA-26-148-01 published
- 2026-05-29: disclosed: CVE-2026-44611 published to NVD