CyberRota Analysis
AI-GeneratedThe vulnerability in OTTO® Fleet Manager arises from an inadequate work factor in its bcrypt password hashing, potentially allowing attackers to execute offline brute-force attacks on stored password hashes. This weakness increases the risk of credential compromise, especially if an unencrypted system backup is accessed. Organizations using this software should prioritize remediation to protect sensitive user credentials from being exploited.
Original NVD Description
A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker gains access to an unencrypted system backup, the weakly hashed credentials could be more easily compromised.