Skip to content
Threat Feed
medium advisory

Insufficient Work Factor in Rockwell Automation OTTO Fleet Manager

Rockwell Automation OTTO Fleet Manager versions V2.36.2 and earlier use an insufficient work factor for bcrypt password hashing, enabling attackers with access to system backups to perform efficient offline brute-force attacks.

CVE search metadata

CVE search record: CVE-2026-75112. EPSS: 0.11%. KEV: no. Product: OTTO Fleet Manager. Brief: Insufficient Work Factor in Rockwell Automation OTTO Fleet Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-08-rockwell-otto-hash/

Rockwell Automation has disclosed a security vulnerability, identified as CVE-2026-75112, affecting the OTTO Fleet Manager software in versions V2.36.2 and earlier. The issue lies in the implementation of the bcrypt password hashing algorithm, which utilizes an insufficient work factor. This deficiency significantly lowers the computational effort required for an attacker to conduct offline brute-force attacks against stored password hashes. The threat is most relevant in scenarios where an attacker successfully obtains a copy of an unencrypted system backup. Because this vulnerability facilitates the compromise of credentials post-exfiltration, it represents a risk to the integrity of account access within industrial environments managed by this software.

Impact

Successful exploitation could result in the compromise of user credentials stored within the OTTO Fleet Manager system. By reducing the computational cost of cracking hashes, attackers can more rapidly gain unauthorized access to the application, potentially impacting critical manufacturing and transportation systems where these units are deployed worldwide. The risk is limited to scenarios involving local or network access to unencrypted backup files.

Recommendation

  • Upgrade all instances of OTTO Fleet Manager to version 2.36.3 or later to remediate the bcrypt work factor deficiency.
  • Enable encrypted system backups in OTTO Fleet Manager configuration as per the guidance in Rockwell Automation security advisory SD1791.
  • Restrict access to system backup files to highly privileged service accounts and implement robust monitoring to detect unauthorized file access or exfiltration.
  • Implement network segmentation to isolate OTTO Fleet Manager instances from broader business networks, limiting the potential for lateral movement and access to sensitive backup data.

Immediate actions

Audit environment for OTTO Fleet Manager version 2.36.2 or earlier

IT Operations 72h

Mitigations

Upgrade to version 2.36.3

immediate IT Operations

CVE-2026-75112