CVE-2026-75112 PUBLISHED

OTTO® Fleet Manager – Weak Password Hashing Configuration

Assigner: Rockwell
Reserved: 17.08.2026 Published: 19.08.2026 Updated: 19.08.2026

A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Rockwell Automation
Product OTTO® Fleet Manager
Versions Default: unaffected
  • Version V2.36.2 and prior is affected

References

Problem Types

  • CWE-916 Use of password hash with insufficient computational effort CWE