Home
MEDIUM: 5.7 CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:LMEDIUM: 6.9 CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 5.250
affected
Description
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.
Problem types
Product status
Any version before 5.250
Credits
Andrew Tierney of Pen Test Partners reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-148-01
github.com/...p/csaf_files/OT/white/2026/icsa-26-148-01.json