All stories
highDefensive GuidanceCVE-2026-10573

Malicious CIP messages can trigger denial of service in Rockwell Automation POINT I/O modules

Crafted CIP messages can force Rockwell Automation 1734 POINT I/O modules into a faulted state, requiring a manual restart. This vulnerability carries a CVSS score of 8.7. If you cannot upgrade immediately, ensure your industrial network is segmented to prevent unauthorized access to these modules.

Summary

A denial-of-service vulnerability has been identified in the Rockwell Automation 1734 POINT I/O module. The flaw stems from improper handling of Common Industrial Protocol (CIP) messages, which can cause the hardware to enter a faulted state and cease normal operations. Once the module enters this state, it cannot recover without a physical or manual restart.

The issue was discovered internally by Rockwell Automation during routine testing. While no active exploitation has been reported in the wild, the high severity reflects the potential for operational disruption in industrial environments.

Technical details

The vulnerability, tracked as CVE-2026-10573, is categorized under CWE-770: Allocation of Resources Without Limits or Throttling. The root cause involves how the 1734 POINT I/O module processes specific CIP messages.

When a specially crafted message is sent to the device, the module fails to handle the resource allocation correctly, leading to a system fault. This disruption halts the module's ability to perform its intended function within an automation system. Because the resulting state is a hardware fault, operators must intervene to restart the unit to restore functionality.

Affected products and fixed versions

The vulnerability specifically impacts the 1734 POINT I/O™ module series. Rockwell Automation has provided specific migration guidance for users of the 8 Point Digital Output Module.

Product Vulnerability Recommended Action
1734 POINT I/O™ CVE-2026-10573 Migrate to 5034-OB8

Why this matters for defenders

In an industrial automation context, a faulted module can halt entire production lines or critical control processes. Because the recovery mechanism requires a restart, an attacker could repeatedly trigger this fault to ensure sustained downtime.

Defenders should focus on protecting the communication paths used by the Common Industrial Protocol (CIP). Since the attack vector involves crafted messages, controlling who can talk to these modules is the primary line of defense.

Defender guidance

If immediate hardware replacement is not feasible, implement the following controls:

  • Network Segmentation: Isolate 1734 POINT I/O modules within protected industrial zones. Ensure that only authorized controllers and engineering workstations can communicate with these devices via CIP.
  • Access Control: Restrict network access to prevent unauthorized or external entities from sending traffic to the module's IP address.
  • Monitor for Faults: Implement logging and alerting for unexpected module faults or sudden transitions to a "faulted" state in your industrial control system (ICS) environment.

For those able to perform hardware updates, Rockwell Automation recommends migrating to the 5034-OB8 model to mitigate the risk.

Sources

  1. https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09
  2. https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1779.html
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -