VYPR
advisoryPublished Aug 27, 2026· 1 source

Rockwell Automation OTTO Fleet Manager Vulnerable to Offline Password Brute-Force Attacks

A medium-severity vulnerability in Rockwell Automation's OTTO Fleet Manager could allow attackers to more easily brute-force password hashes if they obtain an unencrypted system backup.

Rockwell Automation has issued a security advisory for its OTTO Fleet Manager software, detailing a vulnerability that could expose user credentials. The issue, identified as CVE-2026-75112, affects versions up to and including V2.36.2 and carries a CVSS score of 6.8, classifying it as medium severity.

The vulnerability stems from an insufficient computational effort in the bcrypt password hashing implementation. Bcrypt is a widely used algorithm designed to make brute-force attacks computationally expensive. However, when implemented with a low work factor, it significantly reduces the difficulty for an attacker to guess passwords offline if they manage to obtain a system backup containing these hashed credentials.

Successful exploitation requires an attacker to first gain access to an unencrypted system backup of the OTTO Fleet Manager. Once this backup is acquired, the weakened password hashes can be subjected to brute-force attacks, potentially revealing legitimate user credentials. This could then grant the attacker further access to the OTTO Fleet Manager system, which is used for managing fleets of automated guided vehicles (AGVs) in industrial environments.

The affected product, Rockwell Automation OTTO Fleet Manager, is deployed worldwide across critical infrastructure sectors such as critical manufacturing and transportation systems. The potential impact of credential compromise could disrupt operations, lead to unauthorized access to sensitive fleet management data, or enable further lateral movement within an industrial network.

Rockwell Automation has addressed this vulnerability by releasing version V2.36.3 of OTTO Fleet Manager. Users are strongly advised to upgrade to this patched version as soon as possible. For organizations unable to immediately upgrade, Rockwell Automation recommends following their security best practices and consulting their security advisory SD1791 for instructions on enabling encrypted system backups within OTTO Fleet Manager.

While CISA notes that no known public exploitation specifically targeting this vulnerability has been reported, and it is not remotely exploitable, the risk remains significant for any organization using affected versions. The advisory also reiterates general CISA recommendations for securing industrial control systems, including minimizing network exposure, isolating control system networks, and using secure remote access methods like VPNs.

This vulnerability highlights the ongoing importance of robust password hashing implementations and secure backup practices, even in operational technology (OT) environments. The ease with which attackers can obtain and process data from compromised backups underscores the need for comprehensive security strategies that extend beyond network defenses to data protection and integrity.

Synthesized by Vypr AI