PatchSiren cyber security CVE debrief
CVE-2026-10573 Rockwell Automation CVE debrief
A denial-of-service security issue exists in 1734 POINT I/O module from Rockwell Automation. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. This issue affects various industrial control systems that use this module. Organizations using Rockwell Automation 1734 POINT I/O modules should be aware of this vulnerability and take steps to patch or mitigate it. This includes operators of industrial control systems, platform administrators, vulnerability management teams, and security teams. They should review official advisories, assess their exposure, and plan remediation efforts to prevent potential disruptions. The CVE record and source item provide details on the denial-of-service vulnerability in 1734 POINT I/O module. Evidence is based on official CVE and source item records. The vulnerability affects Rockwell Automation 1734 POINT I/O modules, which are used in various industrial control systems. The issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
- Vendor
- Rockwell Automation
- Product
- 1734 POINT I/O
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-21
Who should care
Organizations using Rockwell Automation 1734 POINT I/O modules should be aware of this vulnerability and take steps to patch or mitigate it. This includes operators of industrial control systems, platform administrators, vulnerability management teams, and security teams. They should review official advisories, assess their exposure, and plan remediation efforts to prevent potential disruptions.
Technical summary
The 1734 POINT I/O module from Rockwell Automation is vulnerable to a denial-of-service attack due to improper handling of crafted CIP messages. This can cause the module to enter a faulted state, requiring a restart to recover. The vulnerability affects various industrial control systems that use this module. To mitigate the issue, defenders should review official advisories, plan vendor-supported updates or mitigations, and implement compensating controls.
Defensive priority
Organizations using 1734 POINT I/O modules should prioritize patching, as this denial-of-service vulnerability can disrupt operations.
Recommended defensive actions
- Apply the recommended patch to prevent denial-of-service attacks
- Implement compensating controls to detect and respond to potential attacks
- Monitor system logs for suspicious activity
- Use secure communication protocols to protect CIP messages
- Review and update asset inventory to ensure all affected systems are accounted for
- Conduct exposure review to identify potential vulnerabilities
- Establish a rollback/change window plan for affected systems
Evidence notes
The CVE record and source item provide details on the denial-of-service vulnerability in 1734 POINT I/O module. Evidence is based on official CVE and source item records. The vulnerability affects Rockwell Automation 1734 POINT I/O modules, which are used in various industrial control systems. The issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Official resources
-
CVE-2026-10573 CVE record
CVE.org
-
CVE-2026-10573 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T06:00:00.000Z and has not been modified since then.