PatchSiren cyber security CVE debrief
CVE-2026-44611 Danelec CVE debrief
A medium-severity vulnerability (CVSS 5.9) in Danelec MacGregor Voyage Data Recorder (VDR) systems involves password hashing that limits password length and is susceptible to brute-force attacks. The weakness stems from use of a hashing method that does not provide adequate resistance to password cracking attempts. This affects maritime safety equipment used for recording vessel navigation data. The vulnerability was disclosed by CISA ICS-CERT on May 29, 2026, and is tracked as ICSA-26-148-01.
- Vendor
- Danelec
- Product
- MacGregor Voyage Data Recorder (VDR) G4e
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-28
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-28
Who should care
Maritime operators, shipowners, and fleet managers using Danelec MacGregor VDR systems; ICS security teams responsible for maritime safety equipment; port authorities and classification societies auditing vessel cybersecurity compliance.
Technical summary
The Danelec MacGregor Voyage Data Recorder implements password storage using a hashing method that imposes length limitations on passwords and lacks sufficient computational cost to resist brute-force attacks. The CVSS 4.0 vector (AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N) indicates attack requires adjacent network access, high attack complexity, and low privileges, with high impact to confidentiality of VDR data. The weakness is classified as CWE-916 (Use of Password Hash With Insufficient Computational Effort).
Defensive priority
medium
Recommended defensive actions
- Contact Danelec for patch availability and recommended firmware updates per vendor security advisory
- Review and strengthen password policies for VDR administrative accounts, enforcing maximum length constraints where the hashing method limits input
- Implement network segmentation to limit access to VDR management interfaces from untrusted networks
- Monitor authentication logs for anomalous access attempts to VDR systems
- Conduct security assessment of password storage implementations in other maritime safety equipment
Evidence notes
CISA ICS-CERT advisory ICSA-26-148-01 identifies CWE-916 (Use of Password Hash With Insufficient Computational Effort). CVSS 4.0 vector: AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N. Vendor contact information provided for coordinated disclosure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44611 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44611
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44611 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44611
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-01.json
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-01
-
Source reference
Unverified legacy reference
URL: https://www.danelec.com/contact
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.