CVE-2026-44611
Weak Password Hashing in Danelec MacGregor Voyage Data Recorder
Publication date: 2026-05-29
Last updated on: 2026-05-29
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| danelec | macgregor_voyage_data_recorder | 5.250 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-916 | The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability involves passwords stored with a hashing method that limits password length and is susceptible to brute force attacks. This weakness could potentially lead to unauthorized access to sensitive data recorded by the Danelec MacGregor Voyage Data Recorder.
Such unauthorized access risks compromising confidentiality and integrity of data, which may impact compliance with data protection regulations like GDPR and HIPAA that require adequate protection of personal and sensitive information.
However, the provided information does not explicitly state the direct effects on compliance with these standards or any regulatory consequences.
What immediate steps should I take to mitigate this vulnerability?
The vulnerability involves weak password hashing susceptible to brute force attacks on Danelec MacGregor Voyage Data Recorder devices.
Although no specific mitigation steps are detailed in the provided context, general best practices include limiting access to affected devices, monitoring for unauthorized access attempts, and applying any available firmware updates from the vendor.
Can you explain this vulnerability to me?
This vulnerability involves the Danelec MacGregor Voyage Data Recorder storing passwords using a hashing method that limits the password length and is vulnerable to brute force attacks.
How can this vulnerability impact me? :
Because the password hashing method is weak and limits password length, attackers could potentially use brute force techniques to guess passwords, leading to unauthorized access to the Voyage Data Recorder.