ics-otregulatorNewsThe Broadside1 min read

CISA flags Rockwell 1734 POINT I/O DoS flaw

The operational risk is boring but real: a crafted CIP message can turn a standard I/O module into a production stop.


TL;DR

CISA disclosed CVE-2026-10573, a CVSS 7.5 denial-of-service flaw in Rockwell Automation 1734 POINT I/O version 3.023, deployed worldwide in critical manufacturing. Contractors, primes and subs running the module face a remote crafted-CIP-message path to a faulted state; recovery requires manually restarting affected modules. Rockwell recommends migration to 5034-OB8, while CISA’s notice gives no availability date for that replacement.

CISA’s July 21 ICS advisory is a standard control-system vulnerability notice, not a compliance milestone or enforcement signal. The affected product is specific: Rockwell Automation 1734 POINT I/O version 3.023. The failure mode is also specific enough to matter on a plant floor. Improper handling of crafted Common Industrial Protocol messages can put the module into a faulted state, creating a denial-of-service condition until the module is restarted.

For defense-industrial-base manufacturers and their suppliers, the Monday work is inventory and segmentation. Identify any 1734 POINT I/O 3.023 modules, keep control-system devices off the public internet, isolate control networks from business networks, and put remote access behind maintained VPNs and other controlled paths. Rockwell recommends migration to 5034-OB8; the gap is that CISA’s republication does not give customers a clean availability date for that replacement, so unsupported exposure management may be the actual near-term mitigation.


Published ·Deep Fathom

CISA flags Rockwell 1734 POINT I/O DoS flaw — The Broadside