PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10573 Rockwell Automation CVE debrief

A denial-of-service security issue exists in 1734 POINT I/O module from Rockwell Automation. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. This issue affects various industrial control systems that use this module. Organizations using Rockwell Automation 1734 POINT I/O modules should be aware of this vulnerability and take steps to patch or mitigate it. This includes operators of industrial control systems, platform administrators, vulnerability management teams, and security teams. They should review official advisories, assess their exposure, and plan remediation efforts to prevent potential disruptions. The CVE record and source item provide details on the denial-of-service vulnerability in 1734 POINT I/O module. Evidence is based on official CVE and source item records. The vulnerability affects Rockwell Automation 1734 POINT I/O modules, which are used in various industrial control systems. The issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Vendor
Rockwell Automation
Product
1734 POINT I/O
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-08-27
Advisory published
2026-07-14
Advisory updated
2026-08-27

Who should care

Organizations using Rockwell Automation 1734 POINT I/O modules should be aware of this vulnerability and take steps to patch or mitigate it. This includes operators of industrial control systems, platform administrators, vulnerability management teams, and security teams. They should review official advisories, assess their exposure, and plan remediation efforts to prevent potential disruptions.

Technical summary

The 1734 POINT I/O module from Rockwell Automation is vulnerable to a denial-of-service attack due to improper handling of crafted CIP messages. This can cause the module to enter a faulted state, requiring a restart to recover. The vulnerability affects various industrial control systems that use this module. To mitigate the issue, defenders should review official advisories, plan vendor-supported updates or mitigations, and implement compensating controls.

Defensive priority

Organizations using 1734 POINT I/O modules should prioritize patching, as this denial-of-service vulnerability can disrupt operations.

Recommended defensive actions

  • Apply the recommended patch to prevent denial-of-service attacks
  • Implement compensating controls to detect and respond to potential attacks
  • Monitor system logs for suspicious activity
  • Use secure communication protocols to protect CIP messages
  • Review and update asset inventory to ensure all affected systems are accounted for
  • Conduct exposure review to identify potential vulnerabilities
  • Establish a rollback/change window plan for affected systems

Evidence notes

The CVE record and source item provide details on the denial-of-service vulnerability in 1734 POINT I/O module. Evidence is based on official CVE and source item records. The vulnerability affects Rockwell Automation 1734 POINT I/O modules, which are used in various industrial control systems. The issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10573 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10573

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10573 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10573

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.