news.mlab.sh
Back to the feed
threat-intel

MacGregor Voyage Data Recorder (VDR) G4e

High
Summary

A vulnerability has been identified in MacGregor Voyage Data Recorder (VDR) G4e devices, specifically versions prior to V5.250, due to the use of default credentials, weak password hashing, and hard-coded credentials. This allows an attacker to gain administrator access to the device and potentially modify sensitive authentication files. The vendor, Danelec, has released firmware version V5.250 to address these issues, and CISA recommends immediate updates to mitigate the risk.

The MacGregor VDR G4e device, used in transportation systems worldwide, is vulnerable to unauthorized access due to a combination of factors. Specifically, the device ships with default usernames and passwords that are not changed, and the password hashing algorithm employed is considered weak, making it susceptible to brute-force attacks. Furthermore, hard-coded credentials are present within the device's configuration, providing a direct entry point for malicious actors. CISA, in collaboration with Pen Test Partners, identified these vulnerabilities and has issued an advisory urging immediate action. The vulnerability allows an authenticated user to download a backup containing account data and password hashes, further exacerbating the risk. The vendor, Danelec, has released firmware version V5.250 to resolve these issues, and CISA recommends users update their devices at the earliest service attendance.

Read the full article at CISA Advisories