Rockwell Automation OTTO Fleet Manager versions V2.36.2 and earlier use bcrypt with an insufficient work factor for password hashing. An attacker with access to an unencrypted system backup could perform offline brute-force attacks against stored password hashes at a reduced computational cost. The vulnerability is not remotely exploitable and requires adjacent network access and low privileges.
OTTO Fleet Manager
1 post
Rockwell Automation OTTO Fleet Manager (CVE-2026-75112)