CVE-2026-10573
Awaiting Analysis Awaiting Analysis - Queue

Denial-of-Service in 1734 POINT I/O Module via Crafted CIP Messages

Vulnerability report for CVE-2026-10573, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-14

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-14
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rockwell_automation 1734_point_i_o 3.023

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-10573 is a denial-of-service (DoS) vulnerability affecting the Rockwell Automation 1734 POINT I/O module, specifically the 8 Point Digital Output Module with firmware version 3.023.

The vulnerability occurs due to improper handling of crafted Common Industrial Protocol (CIP) messages. When the module receives these malicious messages, it can enter a faulted state, causing it to stop functioning properly.

To recover from this faulted state, a manual restart of the module is required. The vulnerability is considered high severity, with a CVSS 4.0 base score of 8.7.

Detection Guidance

Detecting this vulnerability on your network or system involves monitoring for crafted Common Industrial Protocol (CIP) messages targeting the 1734 POINT I/O module. Since the module enters a faulted state when exploited, you can look for unexpected module restarts or faulted states in the device logs.

  • Check the module status via the Rockwell Automation Studio 5000 or FactoryTalk software for any faulted states or unexpected restarts.
  • Use network monitoring tools to inspect CIP traffic for malformed or suspicious messages directed at the 1734 POINT I/O module. Tools like Wireshark with CIP protocol dissectors can help identify anomalous traffic.
  • Review the module's event logs for entries indicating repeated faults or restarts, which may suggest exploitation attempts.

There are no specific commands provided in the context, but you can use standard industrial network monitoring tools to capture and analyze CIP traffic. For example, in Wireshark, you can filter for CIP traffic using the filter 'cip' and look for unusual patterns.

Impact Analysis

This vulnerability can impact you in the following ways:

  • Disruption of operations: If the 1734 POINT I/O module enters a faulted state, it can cause downtime in industrial processes that rely on this module for digital output control.
  • Manual intervention required: Recovery from the faulted state requires a physical or remote restart of the module, which may not be immediately possible in all environments, leading to extended downtime.
  • Potential safety risks: In industrial environments, unexpected module failures could lead to unsafe conditions if the module controls critical equipment or processes.
  • No immediate patch available: Since no corrected firmware version is currently available, the vulnerability remains unpatched unless you migrate to a different module or implement recommended workarounds.
Compliance Impact

This vulnerability may impact compliance with common standards and regulations in the following ways:

  • Industrial control system (ICS) security standards: The vulnerability could affect compliance with standards like IEC 62443, NIST SP 800-82, or NERC CIP, which require secure and reliable operation of industrial control systems. A DoS vulnerability that disrupts operations may violate requirements for system availability and resilience.
  • GDPR (General Data Protection Regulation): While GDPR primarily focuses on personal data protection, if the affected module processes or controls systems that handle personal data, a disruption could lead to availability issues. GDPR requires that personal data be processed securely and remain available, so prolonged downtime could raise compliance concerns.
  • HIPAA (Health Insurance Portability and Accountability Act): If the module is used in a healthcare environment to control systems that handle protected health information (PHI), a DoS attack could disrupt access to critical systems. HIPAA requires the availability and integrity of PHI, so unplanned downtime could be a compliance risk.
  • Other sector-specific regulations: Depending on the industry (e.g., energy, manufacturing, or critical infrastructure), this vulnerability could violate regulations that mandate high availability and security of operational technology (OT) systems.

Organizations should assess whether this vulnerability introduces risks to their compliance posture and take appropriate mitigations, such as implementing Rockwell Automation's recommended security best practices or migrating to unaffected hardware.

Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Migrate to the 5034-OB8 module if possible, as it is not affected by this vulnerability.
  • If migration is not feasible, implement Rockwell Automation's security best practices to reduce exposure. This may include network segmentation, firewalls, and access controls to limit unauthorized access to the 1734 POINT I/O module.
  • Monitor the module for faulted states or unexpected restarts, and investigate any anomalies promptly.
  • Restrict network access to the module to only trusted devices and users. Use firewalls or industrial security appliances to block unauthorized CIP traffic.
  • Stay informed about updates or patches from Rockwell Automation by regularly checking their security advisories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10573. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart