Rockwell Automation OTTO Fleet Manager

Summary

A security vulnerability (CVE-2026-75112) has been identified in Rockwell Automation OTTO Fleet Manager versions less than or equal to V2.36.2. This flaw involves the use of insufficient computational effort in password hashing, making offline brute-force attacks against stored hashes easier for attackers. Successful exploitation could lead to the compromise of weakly hashed credentials if an attacker obtains an unencrypted system backup.

IFF Assessment

FOE

The vulnerability allows for easier brute-force attacks against password hashes, which is detrimental to defenders trying to protect stored credentials.

Severity

6.8 Medium

The CVSS score of 6.8 reflects a medium severity vulnerability. The attack requires prior access to unencrypted system backups, but once achieved, the impact on confidentiality and integrity is significant due to easier password cracking.

Defender Context

This vulnerability highlights the critical importance of robust password hashing algorithms and strong computational work factors in protecting sensitive data, especially in operational technology (OT) environments. Defenders should ensure systems are patched promptly and that password policies enforce complexity and regular rotation to mitigate risks from potential offline brute-force attacks.

Read Full Story →