Skip to content
  • NVDA
  • AAPL
  • MSFT
  • AMD
  • TSLA

Rockwell OTTO Fleet Manager Flaw Enables Brute-Force Attacks

CISA advisory highlights insufficient computational effort in password hashing.

By TMRO Staff·1 min read

Key points

  • CISA advisory published 2026-08-27
  • Affects OTTO Fleet Manager <=V2.36.2
  • CVE-2026-75112, CVSS v3 score 6.8
  • Flaw reduces cost of offline brute-force attacks
  • Sectors: Critical Manufacturing, Transportation Systems

What happened

CISA published an advisory on August 27, 2026, regarding a vulnerability in Rockwell Automation's OTTO Fleet Manager. The vulnerability, identified as CVE-2026-75112, stems from the use of password hashes with insufficient computational effort. Successful exploitation could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.

The advisory states that the following versions are affected: OTTO Fleet Manager <=V2.36.2. The CVSS v3 base score is 6.8. The advisory lists Critical Manufacturing and Transportation Systems as the critical infrastructure sectors where the product is deployed.

Why it matters

This vulnerability could allow attackers to more easily crack password hashes, potentially gaining unauthorized access to OTTO Fleet Manager systems. Given the product's deployment in critical manufacturing and transportation sectors, exploitation could disrupt operations or compromise sensitive data. Organizations using affected versions should review the advisory and consider mitigations.

Why it matters

The vulnerability could enable attackers to more easily crack password hashes, potentially leading to unauthorized access to OTTO Fleet Manager systems. Given the product's use in critical manufacturing and transportation, exploitation could have significant operational and security impacts.

Sources

TMRO Report writes original coverage based on the material listed above.