Weak bcrypt work factor in Rockwell Automation OTTO Fleet Manager (CVE‑2026‑75112) reduces offline brute‑force resistance
What It Is — CISA disclosed that OTTO Fleet Manager versions ≤ 2.36.2 use bcrypt with an insufficient work factor, lowering the computational effort required to crack stored password hashes. The issue is catalogued as CVE‑2026‑75112.
Exploitability — CVSS v3 6.8 (High‑Medium). No public exploit is known, but an attacker who obtains an unencrypted system backup can perform offline brute‑force attacks with far less effort.
Affected Products — Rockwell Automation OTTO Fleet Manager ≤ V2.36.2 (used in critical manufacturing and transportation environments).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Logical Access (CC6.1) and Password Management (CC6.2) require strong cryptographic protection of credentials; weak hashing directly violates those criteria.
- Demonstrating timely patch adoption is a core evidence point for continuous compliance monitoring and audit readiness.
- Enterprise buyers increasingly demand proof that OT systems meet SOC 2 credential‑storage standards before awarding contracts.
Recommended Actions
- Apply Rockwell’s remediation patch or upgrade to a version with a bcrypt work factor of at least 12.
- Rotate all passwords and re‑hash them using the updated algorithm.
- Encrypt system backups and restrict backup‑access permissions.
- Record the remediation steps in your SOC 2 evidence repository and map the change to CC6.1/CC6.2 controls.
Source: CISA Advisory – ICSA‑26‑239‑03