VORANT. Threat Intelligence Sign in Get the full feed

Rockwell 1734 POINT I/O DoS Flaw Disclosed

medium vulnerability manufacturing

A CIP message handling flaw in Rockwell Automation 1734 POINT I/O modules can crash the device into a faulted state requiring manual restart.

CISA published an advisory for a denial-of-service vulnerability in Rockwell Automation's 1734 POINT I/O module, version 3.023. The issue stems from improper handling of crafted CIP (Common Industrial Protocol) messages, allowing an attacker to force the module into a faulted state that requires a manual restart to recover, resulting in a loss of availability for affected industrial control systems.

The vulnerability is tracked as CVE-2026-10573 and classified under CWE-770 (Allocation of Resources Without Limits or Throttling). Affected devices are deployed worldwide in the Critical Manufacturing sector. Rockwell Automation recommends migrating to the 5034-OB8 module as the primary remediation; for customers unable to upgrade, standard security best practices are advised. CISA notes no known public exploitation of this vulnerability has been reported at this time, and the standard ICS network isolation and defense-in-depth recommendations apply.

Mentioned in this report

Vulnerabilities CVE-2026-10573

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free