Machine-generated analysis · WAYSCloud LLM
OTTO Fleet Manager versions up to 2.36.2 use a low bcrypt work factor, easing offline password-hash cracking.
Context
Rockwell Automation OTTO Fleet Manager is the affected product. The advisory states that the bcrypt implementation uses an insufficient work factor, lowering the computational effort needed for offline brute-force attacks on stored hashes, especially if an unencrypted system backup is obtained. The vendor released version 2.36.3 that corrects the issue and recommends enabling encrypted backups. The advisory notes the product is deployed worldwide in critical manufacturing and transportation sectors.
Operator considerations
Check: inventory OTTO Fleet Manager installations at version 2.36.2 or earlier.
Isolate: restrict access to system backups and ensure they are encrypted.
Patch: upgrade affected instances to version 2.36.3 or later.
Log: monitor for unauthorized access to backup files.
Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes.
The following versions of Rockwell Automation OTTO Fleet Manager are affected:
OTTO Fleet Manager
Read the full advisory on CISA →