Executive brief
A security vulnerability has been identified in the Rockwell Automation 1734 POINT I/O module, a component used in industrial automation to manage digital signals. An attacker could remotely send specially crafted messages to the device, causing it to crash or enter a faulted state. This results in a complete loss of the module's functionality, which can disrupt industrial processes and requires a manual restart to restore operations.
Technical details
A denial-of-service (DoS) vulnerability exists in the Rockwell Automation 1734 POINT I/O module (specifically catalog number 1734-OB8) due to improper handling of crafted Common Industrial Protocol (CIP) messages. The issue is categorized as CWE-770 (Allocation of Resources Without Limits or Throttling), where malformed inputs cause the module to enter a faulted state. The attack can be executed over the network without authentication or user interaction. Once the module is faulted, it ceases normal operations and requires a physical or remote restart to recover. As of the advisory date, no firmware patch is available for version 3.023; the vendor recommends migrating to the 5034-OB8 hardware.
Affected products
- Rockwell Automation 1734 POINT I/O 3.023
Timeline
- 2026-07-14: advisory: Initial release of Rockwell Automation advisory SD1779
- 2026-07-14: disclosed