CVE-2026-75112
Received Received - Intake

Insufficient bcrypt Work Factor in OTTO Fleet Manager

Vulnerability report for CVE-2026-75112, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Rockwell Automation

Description

A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rockwell_automation otto_fleet_manager *
rockwellautomation otto_fleet_manager to 2.36.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-916 The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Rockwell Automation's OTTO Fleet Manager software. It involves weak password hashing due to an insufficient work factor in the bcrypt implementation, making offline brute-force attacks against stored password hashes easier for attackers.

Detection Guidance

To detect this vulnerability, check the installed version of OTTO Fleet Manager. If it is V2.36.2 or prior, the system is affected. Use commands like 'rpm -qa | grep otto_fleet_manager' on Linux or check installed programs in Windows to verify the version.

Impact Analysis

If an attacker gains access to an unencrypted system backup, they could exploit this weakness to perform offline brute-force attacks and compromise weakly hashed credentials more easily.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially exposing weakly hashed credentials if an attacker gains access to unencrypted system backups. Weak password hashing reduces the effort required for brute-force attacks, increasing the risk of unauthorized access to sensitive data.

Mitigation Strategies

Upgrade OTTO Fleet Manager to version 2.36.3 or later. If upgrading is not possible, enable encrypted system backups using a strong passphrase and follow security best practices for password storage and backup encryption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75112. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart