Impact
The vulnerability originates from an insufficient work factor used in the bcrypt password hashing implementation within OTTO Fleet Manager. This weakness lowers the computational effort needed for an attacker to perform an offline brute‑force attack against the stored password hashes. If an attacker gains access to an unencrypted system backup that contains these hashes, the credentials can be more readily compromised.
Affected Systems
The affected product is Rockwell Automation OTTO Fleet Manager, version 2.36.2 and all earlier releases.
Risk and Exploitability
The overall score of 6.9 on the CVSS indicates a moderate risk. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path is an offline brute‑force attempt against the password hashes obtained from an unencrypted backup; the reduced work factor makes this attack computationally feasible.
OpenCVE Enrichment