PatchSiren cyber security CVE debrief
CVE-2026-44611 Danelec CVE debrief
A medium-severity vulnerability (CVSS 5.9) in Danelec MacGregor Voyage Data Recorder (VDR) systems involves password hashing that limits password length and is susceptible to brute-force attacks. The weakness stems from use of a hashing method that does not provide adequate resistance to password cracking attempts. This affects maritime safety equipment used for recording vessel navigation data. The vulnerability was disclosed by CISA ICS-CERT on May 29, 2026, and is tracked as ICSA-26-148-01.
- Vendor
- Danelec
- Product
- MacGregor Voyage Data Recorder (VDR) G4e
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-29
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-29
- Advisory updated
- 2026-05-29
Who should care
Maritime operators, shipowners, and fleet managers using Danelec MacGregor VDR systems; ICS security teams responsible for maritime safety equipment; port authorities and classification societies auditing vessel cybersecurity compliance.
Technical summary
The Danelec MacGregor Voyage Data Recorder implements password storage using a hashing method that imposes length limitations on passwords and lacks sufficient computational cost to resist brute-force attacks. The CVSS 4.0 vector (AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N) indicates attack requires adjacent network access, high attack complexity, and low privileges, with high impact to confidentiality of VDR data. The weakness is classified as CWE-916 (Use of Password Hash With Insufficient Computational Effort).
Defensive priority
medium
Recommended defensive actions
- Contact Danelec for patch availability and recommended firmware updates per vendor security advisory
- Review and strengthen password policies for VDR administrative accounts, enforcing maximum length constraints where the hashing method limits input
- Implement network segmentation to limit access to VDR management interfaces from untrusted networks
- Monitor authentication logs for anomalous access attempts to VDR systems
- Conduct security assessment of password storage implementations in other maritime safety equipment
Evidence notes
CISA ICS-CERT advisory ICSA-26-148-01 identifies CWE-916 (Use of Password Hash With Insufficient Computational Effort). CVSS 4.0 vector: AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N. Vendor contact information provided for coordinated disclosure.
Official resources
Disclosed May 29, 2026 via CISA ICS-CERT advisory ICSA-26-148-01.