Rockwell Automation OTTO Fleet Manager
CISA warns Rockwell Automation OTTO Fleet Manager (CVE-2026-75112, CVSS 6.8) uses insufficiently costly password hashing, easing offline brute-force attacks.
CISA published ICS advisory ICSA-26-239-03 for Rockwell Automation OTTO Fleet Manager versions 2.36.2 and earlier (CVE-2026-75112, CVSS v3 6.8). The flaw involves use of a password hash with insufficient computational effort, reducing the cost for an attacker to perform offline brute-force attacks against stored password hashes. Deployments span critical manufacturing and transportation systems sectors worldwide, with company headquarters in the United States.
- CVE-2026-75112 (CVSS 6.8): password hash with insufficient computational effort
- Flaw eases offline brute-force attacks against stored password hashes
- Affects OTTO Fleet Manager 2.36.2 and earlier, deployed worldwide
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-75112 | Insufficient bcrypt Work Factor Weakens Passwords in Rockwell OTTO Fleet Manager CVE-2026-75112 is a weak password-hashing flaw (CWE-916) in Rockwell Automation's OTTO Fleet Manager, caused by an insufficient work factor in its bcrypt implementation that lowers the computational cost required to crack stored password hashes. The issue is triggered when an attacker obtains an unencrypted system backup that contains the weakly hashed user credentials. With that backup in hand, the attacker can conduct offline brute-force or dictionary attacks far more cheaply than expected, potentially recovering passwords and gaining access to the Fleet Manager system (confidentiality-only impact, per the CVSS 4.0 score of 6.9 with VC:H and no integrity or availability impact). Affected users are deployments of OTTO Fleet Manager whose stored password hashes use the insufficient work factor; the available data does not specify affected or fixed version ranges. No exploitation is known at this time: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.1% probability of exploitation within the next 30 days. Do: Monitor Rockwell Automation's security advisory/knowledge base article for CVE-2026-75112 and update OTTO Fleet Manager to the patched release once the vendor publishes fixed version details. In the meantime, encrypt system backups (or restrict access to them) so stored password hashes cannot be harvested for offline cracking, and limit adjacent network and low-privileged access to Fleet Manager. If any unencrypted backup has been exposed or shared, rotate affected user credentials and ensure strong, unique passwords are in use. | 6.9 | <1% |
| nichelikely hundreds to low-thousands of sites (estimate; no public install counts available) |
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automation OTTO Fleet Manager are affected: OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112) CVSS Vendor Equipment Vulnerabilities v3 6.8 Rockwell Automation Rockwell Automation OTTO Fleet Manager Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All…
This source does not provide full text. Read it at cisa.gov.