PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-42951 Danelec CVE debrief

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

Vendor
Danelec
Product
MacGregor Voyage Data Recorder (VDR) G4e
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-28
Advisory published
2026-05-28
Advisory updated
2026-05-28

Who should care

Maritime operators, shipboard IT/OT security teams, fleet management security personnel, and organizations utilizing Danelec MacGregor VDR systems for vessel voyage data recording. This vulnerability affects operational technology environments where VDR systems are deployed for regulatory compliance and incident investigation. Organizations subject to maritime safety regulations (IMO SOLAS VDR requirements) should prioritize assessment due to potential credential exposure affecting device integrity.

Technical summary

The Danelec MacGregor Voyage Data Recorder (VDR) allows authenticated users to download device backups that contain sensitive account data and password hashes. The vulnerability is classified under CWE-522 (Insufficiently Protected Credentials). The CVSS 4.0 score of 5.9 (MEDIUM) reflects attack vector via adjacent network, high attack complexity, low privileges required, and high confidentiality impact on the vulnerable component. No integrity or availability impact is scored. The vulnerability was disclosed via CISA ICS Advisory ICSA-26-148-01 on 2026-05-29.

Defensive priority

medium

Recommended defensive actions

  • Review CISA ICS Advisory ICSA-26-148-01 for vendor guidance and patch availability
  • Restrict network access to VDR devices to authorized personnel only
  • Monitor for unauthorized backup download attempts
  • Audit existing VDR backups for exposure of credential data
  • Rotate credentials for affected VDR accounts if compromise is suspected
  • Contact Danelec for security updates per vendor guidance

Evidence notes

CISA ICS Advisory ICSA-26-148-01 published 2026-05-29. CVSS 4.0 vector: AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N. CWE-522 (Insufficiently Protected Credentials).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-42951 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-42951

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-42951 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42951

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.