IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation OTTO Fleet Manager

MEDIUM
CVSS 6.8
Date 2026-08-27T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-75112 6.8 medium
A security issue exists within OTTO Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.

// Remediations (5)

Mitigation: Rockwell Automation has addressed this vulnerability in software version 2.36.3.
Rockwell Automation has addressed this vulnerability in software version 2.36.3.
Patch: See Rockwell Automation security advisory SD1791 for more information about this issue and instructi
See Rockwell Automation security advisory SD1791 for more information about this issue and instructions to enable encrypted system backup in OTTO Fleet Manager.
Mitigation: If you have any questions regarding this disclosure, please email Rockwell Automation PSIRT: rasecur
If you have any questions regarding this disclosure, please email Rockwell Automation PSIRT: [email protected]
Mitigation: Users of the affected software who are not able to upgrade to the corrected version or apply the mit
Users of the affected software who are not able to upgrade to the corrected version or apply the mitigations should use Rockwell Automation's security best practices.
Mitigation: If you have any questions regarding the security issue(s) above and how to mitigate them, contact Ro
If you have any questions regarding the security issue(s) above and how to mitigate them, contact Rockwell Automation support.

// References