Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Weak bcrypt work factor in Rockwell Automation OTTO Fleet Manager (CVE-2026-75112) eases offline password cracking

A CISA advisory flags CVE‑2026‑75112 in Rockwell Automation’s OTTO Fleet Manager (≤ V2.36.2) where bcrypt is configured with an insufficient work factor, reducing the effort needed for offline brute‑force attacks on stored password hashes. The flaw primarily impacts critical manufacturing and transportation operators and underscores the need for robust credential‑storage controls in SOC 2‑aligned environments.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Weak bcrypt work factor in Rockwell Automation OTTO Fleet Manager (CVE‑2026‑75112) reduces offline brute‑force resistance

What It Is — CISA disclosed that OTTO Fleet Manager versions ≤ 2.36.2 use bcrypt with an insufficient work factor, lowering the computational effort required to crack stored password hashes. The issue is catalogued as CVE‑2026‑75112.

Exploitability — CVSS v3 6.8 (High‑Medium). No public exploit is known, but an attacker who obtains an unencrypted system backup can perform offline brute‑force attacks with far less effort.

Affected Products — Rockwell Automation OTTO Fleet Manager ≤ V2.36.2 (used in critical manufacturing and transportation environments).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Logical Access (CC6.1) and Password Management (CC6.2) require strong cryptographic protection of credentials; weak hashing directly violates those criteria.
  • Demonstrating timely patch adoption is a core evidence point for continuous compliance monitoring and audit readiness.
  • Enterprise buyers increasingly demand proof that OT systems meet SOC 2 credential‑storage standards before awarding contracts.

Recommended Actions

  • Apply Rockwell’s remediation patch or upgrade to a version with a bcrypt work factor of at least 12.
  • Rotate all passwords and re‑hash them using the updated algorithm.
  • Encrypt system backups and restrict backup‑access permissions.
  • Record the remediation steps in your SOC 2 evidence repository and map the change to CC6.1/CC6.2 controls.

Source: CISA Advisory – ICSA‑26‑239‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-03 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →