PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44611 Danelec CVE debrief

A medium-severity vulnerability (CVSS 5.9) in Danelec MacGregor Voyage Data Recorder (VDR) systems involves password hashing that limits password length and is susceptible to brute-force attacks. The weakness stems from use of a hashing method that does not provide adequate resistance to password cracking attempts. This affects maritime safety equipment used for recording vessel navigation data. The vulnerability was disclosed by CISA ICS-CERT on May 29, 2026, and is tracked as ICSA-26-148-01.

Vendor
Danelec
Product
MacGregor Voyage Data Recorder (VDR) G4e
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-29
Original CVE updated
2026-05-29
Advisory published
2026-05-29
Advisory updated
2026-05-29

Who should care

Maritime operators, shipowners, and fleet managers using Danelec MacGregor VDR systems; ICS security teams responsible for maritime safety equipment; port authorities and classification societies auditing vessel cybersecurity compliance.

Technical summary

The Danelec MacGregor Voyage Data Recorder implements password storage using a hashing method that imposes length limitations on passwords and lacks sufficient computational cost to resist brute-force attacks. The CVSS 4.0 vector (AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N) indicates attack requires adjacent network access, high attack complexity, and low privileges, with high impact to confidentiality of VDR data. The weakness is classified as CWE-916 (Use of Password Hash With Insufficient Computational Effort).

Defensive priority

medium

Recommended defensive actions

  • Contact Danelec for patch availability and recommended firmware updates per vendor security advisory
  • Review and strengthen password policies for VDR administrative accounts, enforcing maximum length constraints where the hashing method limits input
  • Implement network segmentation to limit access to VDR management interfaces from untrusted networks
  • Monitor authentication logs for anomalous access attempts to VDR systems
  • Conduct security assessment of password storage implementations in other maritime safety equipment

Evidence notes

CISA ICS-CERT advisory ICSA-26-148-01 identifies CWE-916 (Use of Password Hash With Insufficient Computational Effort). CVSS 4.0 vector: AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N. Vendor contact information provided for coordinated disclosure.

Official resources

Disclosed May 29, 2026 via CISA ICS-CERT advisory ICSA-26-148-01.