Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75112— OTTO® Fleet Manager – Weak Password Hashing Configuration

Quick assessment

Affected
Rockwell Automation OTTO® Fleet Manager
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OTTO® Fleet Manager 存在一个安全问题。该漏洞源于 bcrypt 密码哈希实现中使用的迭代因子(work factor)不足,这可能导致攻击者在针对存储的密码哈希进行离线暴力破解攻击时所需的计算成本降低。如果攻击者能够访问未经加密的系统备份,那么这些经过弱哈希处理的凭证将更容易被破解。

CVSS 6.9 · Medium EPSS 0.11% · P2

Affected Version Matrix 1

VendorProduct Version RangeStatus
Rockwell Automation OTTO® Fleet Manager V2.36.2 and prior affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75112

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OTTO® Fleet Manager – Weak Password Hashing Configuration
Source: CVE Program / CVE List V5
Vulnerability Description
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用具有不充分计算复杂性的口令哈希
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Rockwell Automation OTTO® Fleet Manager V2.36.2 and prior -

II. Public POCs for CVE-2026-75112

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75112

登录查看更多情报信息。

Vendor Advisories for CVE-2026-75112 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75112

No comments yet


Leave a comment