DoseFix LIVE
0votes
Security·United States·CONFIRMED

CISA Advisory: Rockwell Automation OTTO Fleet Manager Vulnerability CVE-2026-75112

United States·
DoseFix EditorialMulti-source synthesis

CISA released an advisory on August 27, 2026, regarding a vulnerability in Rockwell Automation OTTO Fleet Manager, identified as CVE-2026-75112. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, weakly hashed credentials could be more easily compromised. The affected product is OTTO Fleet Manager versions up to and including V2.36.2. Rockwell Automation has addressed the vulnerability in software version 2.36.3. The vulnerability has a CVSS v3.1 base score of 6.8 (Medium) and CVSS v4.0 base score of 6.9 (Medium). It is not exploitable remotely and no public exploitation has been reported. CISA recommends defensive measures such as minimizing network exposure and following vendor mitigations.

1 sources
United States

What we know

Vulnerability is due to insufficient work factor in bcrypt password hashing.

1 sources

Successful exploitation could reduce computational cost for offline brute-force attacks on password hashes.

1 sources

CVSS v3.1 base score: 6.8 (Medium); CVSS v4.0 base score: 6.9 (Medium).

1 sources

Affected product: Rockwell Automation OTTO Fleet Manager versions <= V2.36.2.

1 sources

Rockwell Automation fixed the vulnerability in version 2.36.3.

1 sources

CISA published an advisory on 2026-08-27 for CVE-2026-75112.

1 sources

Attack requires access to unencrypted system backup.

1 sources

Vulnerability is not exploitable remotely.

1 sources
Advisory Timeline

CISA published an advisory for a medium-severity vulnerability in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) due to insufficient bcrypt work factor, potentially enabling offline brute-force attacks on password hashes. Fixed in version 2.36.3.

Verified · 1 sources

Live reports

View all
Advisory TimelineLocal voice · United States
Verified

Comments 0

Discuss this event in persistent threads. Live chat remains separate.

Keep discussion civil and distinguish opinion from verified information.

No comments yet. Start the conversation.

CISA Advisory: Rockwell Automation OTTO Fleet Manager Vulnerability CVE-2026-75112 | DoseFix