IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation 1734 POINT I/O (Update A)

LOW
CVSS 3.7
Date 2026-09-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-10573 3.7 low
A denial-of-service security issue exists in 1734 POINT I/O module. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. When there is only a single IO module is attached, a restart is required to recover. When more than one I/O module is physically attached, the connection automatically recovers within ~5– 7 seconds.

// Remediations (3)

Mitigation: Rockwell Automation recommends users are to migrate to 5034-OB8.
Rockwell Automation recommends users are to migrate to 5034-OB8.
Mitigation: Customers using the affected software, who are not able to upgrade to one of the corrected versions,
Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight).
Mitigation: For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.co
For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.

// References