Rockwell Automation 1734 POINT I/O
CISA advisory warns of a high-severity denial-of-service flaw in Rockwell Automation 1734 POINT I/O modules that can be triggered remotely via crafted CIP messages, requiring a restart to recover.
Intelligence analysis by Llama
ICS Advisory ICSA-26-202-09 covers CVE-2026-10573, a denial-of-service vulnerability in Rockwell Automation 1734 POINT I/O version 3.023. The flaw scores 7.5 (HIGH) on CVSS v3.1 and 8.7 (HIGH) on CVSS v4.0, and Rockwell recommends migrating to 5034-OB8.
Imagine a robot in a factory that listens for messages from its boss computer. A bully can shout a weird message that makes the robot freeze and need a restart. This advisory warns factory owners about that bully trick so they can switch to a newer robot or lock the doors.
Analysis
A Remotely Triggered Industrial Stutter
The vulnerability tracked as CVE-2026-10573 lives inside the firmware of Rockwell Automation's 1734 POINT I/O module, a widely deployed distributed I/O platform used on factory floors and process plants. According to the advisory, the issue stems from improper handling of crafted CIP (Common Industrial Protocol) messages. When a specially formed packet reaches the module, it forces the device into a faulted state, and the only way to restore normal operation is a physical restart. That last detail matters: this is not a soft crash that clears itself. On an active production line, a faulted I/O module can mean a halted cell, a blocked conveyor, or a tripped safety interlock, depending on what that module is wired into.
Why the Scoring Bumped Between CVSS Versions
CISA lists two scores for the same defect: 7.5 (HIGH) on CVSS v3.1 and 8.7 (HIGH) on CVSS v4.0. The vector strings tell the story. Both flag network attack vector, low complexity, no privileges required, and no user interaction, with the only impact being availability. CVSS v4.0 simply weights the availability-only outcome more heavily and refines the scoring, which is why a bug that scores "merely" 7.5 in the older framework lands closer to 9 in the newer one. For asset owners, the practical takeaway is unchanged: a remote, unauthenticated attacker can knock these modules offline without ever holding credentials or tricking a human.
What Operators Should Actually Do
Rockwell's primary fix is hardware-level: migrate to the 5034-OB8 module. For plants that cannot swap hardware immediately, the vendor points operators to its industrial security best-practices document, which is largely a network-hygiene playbook. CISA reinforces that guidance with its standard ICS defensive measures: keep control-system devices off the public internet, place them behind firewalls, isolate them from corporate networks, and use VPNs with current patches when remote access is unavoidable. No public exploitation has been reported, but the disclosure window between a public advisory and active scanning tends to be short for OT bugs, so the advisory reads less like a warning and more like a checklist for the next maintenance window.
Key points
- CVE-2026-10573 is a denial-of-service flaw in Rockwell Automation 1734 POINT I/O version 3.023 triggered by crafted CIP messages.
- The vulnerability scores 7.5 (HIGH) on CVSS v3.1 and 8.7 (HIGH) on CVSS v4.0, with no required privileges or user interaction.
- A successful exploit forces the module into a faulted state that only a restart can clear, risking production halts on factory floors.
- Rockwell recommends migrating to the 5034-OB8 module and otherwise following its industrial security best-practices guidance.
- No public exploitation has been reported, but the bug affects equipment deployed in critical manufacturing sectors worldwide.
Because the flaw requires only availability impact, no credentials, and no user interaction, defenders can prioritize patching and network segmentation over complex incident response. Migrating to the 5034-OB8 replacement module is a clean, hardware-level fix, and the absence of any reported public exploitation gives plant teams a window to act before attackers weaponize the bug.
Many POINT I/O installations sit on plant floors with long change-control windows, meaning unpatched modules may remain exposed through the next scheduled outage. The faulted-state condition requires a physical restart, so a single attacker with network reach could repeatedly knock modules offline, turning a single CVE into a chronic reliability problem for the affected line.



