Danelec MacGregor Voyage Data Recorder
cpe:2.3:h:macgregor:interschalt_vdr_g4e:*:*:*:*:*:*:*, +1 more
- < V5.250
A vulnerability exists in the Danelec MacGregor Voyage Data Recorder (VDR) G4e devices prior to version 5.250, allowing for unauthorized access due to the presence of default usernames and passwords, with no requirement for users to change them. This issue is compounded by the device's web interface, which permits direct editing of sensitive authentication-related files, potentially enabling unauthorized password changes.
Exploitation of this vulnerability could lead to unauthorized administrator access on the affected device.
Danelec has released firmware version 5.250 to address this vulnerability. Users are advised to update their devices at the earliest opportunity. For more information, contact Danelec through their website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.