Denial‑of‑Service Vulnerability (CVE‑2026‑10573) in Rockwell Automation 1734 POINT I/O Threatens Critical Manufacturing Operations
What It Is — Rockwell Automation disclosed CVE‑2026‑10573, a flaw in the 1734 POINT I/O module (firmware 3.023) that mishandles crafted Common Industrial Protocol (CIP) messages, forcing the device into a faulted state that requires a manual restart.
Exploitability — CVSS v3.1 7.5 (High). No public exploit code is known, but the vulnerability is trivially triggered by sending malformed CIP traffic, making on‑network exploitation realistic for an adversary with access to the control‑system LAN.
Affected Products — Rockwell Automation 1734 POINT I/O (firmware 3.023).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Control CC6.1 (System Operations) requires documented patch‑management and evidence that critical OT assets are kept up‑to‑date; a known DoS flaw undermines that evidence.
- Continuous control monitoring must capture configuration drift and unpatched firmware as auditable proof of due diligence, especially for customers in the Critical Manufacturing sector.
- Enterprise buyers increasingly demand proof that OT environments are covered by the same rigorous SOC 2 controls applied to IT, making this vulnerability a red flag in vendor risk assessments.
Recommended Actions
- Map the DoS flaw to SOC 2 CC6.1 and CC7.1 (Change Management) controls; record the gap in your control inventory.
- Deploy the vendor‑recommended firmware upgrade (or the interim mitigation guide) and capture the upgrade logs as immutable audit evidence.
- Enable continuous monitoring of OT firmware versions and alert on any re‑introduction of the vulnerable 3.023 release.
- Validate that your incident‑response playbook includes a DoS recovery procedure for the 1734 POINT I/O module.
Source: CISA Advisory – ICSA‑26‑202‑09