PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44611 Danelec CVE debrief

A medium-severity vulnerability (CVSS 5.9) in Danelec MacGregor Voyage Data Recorder (VDR) systems involves password hashing that limits password length and is susceptible to brute-force attacks. The weakness stems from use of a hashing method that does not provide adequate resistance to password cracking attempts. This affects maritime safety equipment used for recording vessel navigation data. The vulnerability was disclosed by CISA ICS-CERT on May 29, 2026, and is tracked as ICSA-26-148-01.

Vendor
Danelec
Product
MacGregor Voyage Data Recorder (VDR) G4e
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-28
Advisory published
2026-05-28
Advisory updated
2026-05-28

Who should care

Maritime operators, shipowners, and fleet managers using Danelec MacGregor VDR systems; ICS security teams responsible for maritime safety equipment; port authorities and classification societies auditing vessel cybersecurity compliance.

Technical summary

The Danelec MacGregor Voyage Data Recorder implements password storage using a hashing method that imposes length limitations on passwords and lacks sufficient computational cost to resist brute-force attacks. The CVSS 4.0 vector (AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N) indicates attack requires adjacent network access, high attack complexity, and low privileges, with high impact to confidentiality of VDR data. The weakness is classified as CWE-916 (Use of Password Hash With Insufficient Computational Effort).

Defensive priority

medium

Recommended defensive actions

  • Contact Danelec for patch availability and recommended firmware updates per vendor security advisory
  • Review and strengthen password policies for VDR administrative accounts, enforcing maximum length constraints where the hashing method limits input
  • Implement network segmentation to limit access to VDR management interfaces from untrusted networks
  • Monitor authentication logs for anomalous access attempts to VDR systems
  • Conduct security assessment of password storage implementations in other maritime safety equipment

Evidence notes

CISA ICS-CERT advisory ICSA-26-148-01 identifies CWE-916 (Use of Password Hash With Insufficient Computational Effort). CVSS 4.0 vector: AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N. Vendor contact information provided for coordinated disclosure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44611 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44611

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44611 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44611

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.