CVE-2026-44611 PUBLISHED

MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computational Effort

Assigner: icscert
Reserved: 07.05.2026 Published: 29.05.2026 Updated: 29.05.2026

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.9

Product Status

Vendor Danelec
Product MacGregor Voyage Data Recorder (VDR) G4e
Versions Default: unaffected
  • affected from 0 to 5.250 (excl.)

Solutions

Danelec has released firmware version V5.250 to resolve these vulnerabilities. Users of MacGregor Voyage Data Recorder (VDR) G4e devices are encouraged to update the firmware at the earliest service attendance rather than waiting for an annual performance test. Contact Danelec with additional questions:  https://www.danelec.com/contact

Credits

  • Andrew Tierney of Pen Test Partners reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-916 Use of Password Hash With Insufficient Computational Effort CWE