Rockwell Automation OTTO Fleet Manager
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell Automation OTTO Fleet Manager are affected: OTTO Fleet Manager <=V2.36.2 (CVE-2026-75112) CVSS Vendor Equipment Vulnerabilities v3 6.8 Rockwell Automation Rockwell Automation OTTO Fleet Manager Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Critical Manufacturing, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-75112 A security issue exists within OTTO Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised. View CVE Details Affected Products Rockwell Automation OTTO Fleet Manager Vendor: Rockwell Automation Product Version: Rockwell Automation OTTO Fleet Manager: <=V2.36.2 Product Status: known_affected Remediations Mitigation Rockwell Automation has addressed this vulnerability in software version 2.36.3. https://file-share.ottomotors.com/login Mitigation Users of the affected software who are not able to upgrade to the corrected version or apply the mitigations should use Rockwell Automation's security best practices. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Vendor fix See Rockwell Automation security advisory SD1791 for more information about this issue and instructions to enable encrypted system backup in OTTO Fleet Manager. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/adv
CSIRTS triage
- What
- The bcrypt password hashing implementation uses insufficient computational work factor, reducing the cost for offline brute-force attacks against stored password hashes.
- Who is affected
- Deployments of Rockwell Automation OTTO Fleet Manager version 2.36.2 and earlier, used in critical manufacturing and transportation systems worldwide.
- Urgency
- Critical severity and CVSS 6.8 require immediate patching, though no active exploitation is documented.
- Action
- Upgrade to a version above 2.36.2 that implements proper bcrypt work factors.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OTTO Fleet Manager
Get an email when a new OTTO Fleet Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-751120.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-75112 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CISA Cybersecurity Advisories
- criticalInductive Automation Ignition2026-09-03
- criticalOPCFoundation OPC UA LocalDiscoveryServer (LDS)2026-09-03
- criticalRockwell Automation ControlFLASH2026-09-03
- criticalRockwell Automation ArmorStart LT2026-09-03
- criticalRockwell Automation 1756-ENBT Module2026-09-03