Description
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.
Published: 2026-08-19
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from an insufficient work factor used in the bcrypt password hashing implementation within OTTO Fleet Manager. This weakness lowers the computational effort needed for an attacker to perform an offline brute‑force attack against the stored password hashes. If an attacker gains access to an unencrypted system backup that contains these hashes, the credentials can be more readily compromised.

Affected Systems

The affected product is Rockwell Automation OTTO Fleet Manager, version 2.36.2 and all earlier releases.

Risk and Exploitability

The overall score of 6.9 on the CVSS indicates a moderate risk. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path is an offline brute‑force attempt against the password hashes obtained from an unencrypted backup; the reduced work factor makes this attack computationally feasible.

Generated by OpenCVE AI on August 20, 2026 at 12:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OTTO Fleet Manager to a version that implements a stronger bcrypt work factor
  • Reconfigure the application to use a bcrypt work factor that meets current security recommendations
  • Encrypt all system backups to prevent exploitation of stored password hashes

Generated by OpenCVE AI on August 20, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.
Title OTTO® Fleet Manager – Weak Password Hashing Configuration
First Time appeared Rockwell Automation
Rockwell Automation otto Fleet Manager
Weaknesses CWE-916
CPEs cpe:2.3:a:rockwell_automation:otto_fleet_manager:v2.36.2_and_prior:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation otto Fleet Manager
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Otto Fleet Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-08-19T19:28:28.710Z

Reserved: 2026-08-17T17:32:48.971Z

Link: CVE-2026-75112

cve-icon Vulnrichment

Updated: 2026-08-19T19:28:25.375Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T20:17:23.037

Modified: 2026-08-28T18:58:27.140

Link: CVE-2026-75112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:45:03Z

Weaknesses
  • CWE-916

    Use of Password Hash With Insufficient Computational Effort