HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High ThreatIntel

Denial‑of‑Service Vulnerability (CVE‑2026‑10573) in Rockwell Automation 1734 POINT I/O Threatens Critical Manufacturing Operations

Rockwell Automation disclosed CVE‑2026‑10573, a high‑severity DoS flaw in its 1734 POINT I/O module (firmware 3.023). The issue can be triggered by malformed CIP traffic, forcing the device into a faulted state and requiring a restart. For manufacturers subject to SOC 2, the vulnerability highlights gaps in patch‑management and continuous control monitoring.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 cisa.gov
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Denial‑of‑Service Vulnerability (CVE‑2026‑10573) in Rockwell Automation 1734 POINT I/O Threatens Critical Manufacturing Operations

What It Is — Rockwell Automation disclosed CVE‑2026‑10573, a flaw in the 1734 POINT I/O module (firmware 3.023) that mishandles crafted Common Industrial Protocol (CIP) messages, forcing the device into a faulted state that requires a manual restart.

Exploitability — CVSS v3.1 7.5 (High). No public exploit code is known, but the vulnerability is trivially triggered by sending malformed CIP traffic, making on‑network exploitation realistic for an adversary with access to the control‑system LAN.

Affected Products — Rockwell Automation 1734 POINT I/O (firmware 3.023).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Control CC6.1 (System Operations) requires documented patch‑management and evidence that critical OT assets are kept up‑to‑date; a known DoS flaw undermines that evidence.
  • Continuous control monitoring must capture configuration drift and unpatched firmware as auditable proof of due diligence, especially for customers in the Critical Manufacturing sector.
  • Enterprise buyers increasingly demand proof that OT environments are covered by the same rigorous SOC 2 controls applied to IT, making this vulnerability a red flag in vendor risk assessments.

Recommended Actions

  • Map the DoS flaw to SOC 2 CC6.1 and CC7.1 (Change Management) controls; record the gap in your control inventory.
  • Deploy the vendor‑recommended firmware upgrade (or the interim mitigation guide) and capture the upgrade logs as immutable audit evidence.
  • Enable continuous monitoring of OT firmware versions and alert on any re‑introduction of the vulnerable 3.023 release.
  • Validate that your incident‑response playbook includes a DoS recovery procedure for the 1734 POINT I/O module.

Source: CISA Advisory – ICSA‑26‑202‑09

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-09

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →