Insufficient Password Hashing in OTTO® Fleet Manager by Rockwell Automation
CVE-2026-75112

6.9MEDIUM

Key Information:

Vendor
CVE Published:
19 August 2026

What is CVE-2026-75112?

A vulnerability exists in OTTO® Fleet Manager that originates from the use of an inadequate work factor in the bcrypt password hashing method. This flaw allows attackers to execute offline brute-force attacks more efficiently against stored password hashes. If an attacker obtains access to an unprotected system backup, the credentials protected by weak hashing mechanisms could be compromised with relative ease, posing a significant risk to user accounts and overall system security.

Affected Version(s)

OTTO® Fleet Manager V2.36.2 and prior

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.