Rockwell Automation OTTO Fleet Manager

MonitorCVSS 6.8ICS-CERT ICSA-26-239-03Aug 19, 2026
Rockwell Automation
Summary

OTTO Fleet Manager uses weak password hashing configuration in its user authentication system. This allows an attacker who gains access to the application database to crack user passwords offline, potentially leading to unauthorized access and control of the autonomous mobile robot fleet.

What this means
What could happen
An attacker with access to the OTTO Fleet Manager database could crack user passwords due to weak hashing, potentially gaining unauthorized access to the fleet management system and the autonomous mobile robots it controls.
Who's at risk
Operators and managers of Rockwell Automation OTTO autonomous mobile robot fleets who use the OTTO Fleet Manager application for fleet oversight and command. This affects organizations in warehousing, manufacturing, logistics, and materials handling that depend on robot fleet availability and correct operation.
How it could be exploited
An attacker with database access (either through a separate vulnerability, misconfigured backup, or stolen database file) can extract password hashes from OTTO Fleet Manager. Because weak hashing is used, passwords can be cracked offline using readily available tools, allowing the attacker to log in as a legitimate user and command the fleet.
Prerequisites
  • Access to the OTTO Fleet Manager database or backups
  • Ability to extract password hashes from the database
No patch availableWeak authentication mechanismDatabase-level access required for exploitationAffects fleet control and routing decisions
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (1)
ProductAffected VersionsFix Status
OTTO Fleet ManagerAll versionsNo fix (EOL)
Remediation & Mitigation
0/5
Do now
0/3
HARDENINGRestrict database access to OTTO Fleet Manager to authorized personnel only via firewall rules and network segmentation
HARDENINGEnforce strong password policies for all OTTO Fleet Manager accounts (minimum 12 characters, complexity requirements)
WORKAROUNDDisable or restrict remote access to the OTTO Fleet Manager database; require local network access only
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HARDENINGImplement database encryption at rest for OTTO Fleet Manager data files and backups
HARDENINGMonitor database access logs for unauthorized login attempts and unusual authentication activity
API: /api/v1/advisories/1699ec6f-61e5-4227-b8ed-8423bf5aa7ab

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation OTTO Fleet Manager | CVSS 6.8 - OTPulse