Rockwell Automation 1734 POINT I/O

MonitorCVSS 7.5ICS-CERT ICSA-26-202-09Jul 14, 2026
Rockwell Automation
Summary

The Rockwell 1734 POINT I/O module contains a vulnerability in its CIP object message handling. When a malformed or invalid CIP message is received, the device fails to properly validate the input and enters a non-responsive state. This causes a denial of service condition affecting all I/O operations on that module. The module must be manually rebooted to restore functionality. No security update is available from Rockwell for this issue.

What this means
What could happen
An attacker could send specially crafted network messages to a 1734 POINT I/O module, causing it to stop responding and halt I/O operations until it is manually rebooted. This would interrupt any process that depends on those input or output signals.
Who's at risk
Water utilities and municipal electric systems that use Rockwell 1734 POINT I/O modules for remote input/output operations, including pump stations, tank level monitoring, breaker status feedback, and valve control signals. Any facility relying on EtherNet/IP-connected distributed I/O for process automation is at risk.
How it could be exploited
An attacker with network access to the 1734 POINT I/O module sends a malformed CIP (Common Industrial Protocol) object message to the device. The module fails to validate the input and crashes, becoming unresponsive to normal I/O requests. The attacker does not need credentials or special knowledge of process operations.
Prerequisites
  • Network access to the 1734 POINT I/O module on port 2222 (EtherNet/IP default) or via a connected control network
  • Ability to craft and send CIP protocol messages to the device
remotely exploitableno authentication requiredno patch availableaffects safety systems
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (2)
1 pending1 EOL
ProductAffected VersionsFix Status
1734 POINT I/OAll versionsNo fix (EOL)
1734 POINT I/O: 3.0233.023No fix yet
Remediation & Mitigation
0/4
Do now
0/2
1734 POINT I/O
WORKAROUNDRestrict network access to 1734 POINT I/O modules: configure network switches and firewalls to block incoming EtherNet/IP traffic (port 2222/TCP and 2222/UDP) from untrusted subnets
WORKAROUNDEstablish a maintenance window procedure to rapidly identify and reboot 1734 POINT I/O modules if they become unresponsive, and log all reboot events for forensic analysis
Mitigations - no patch available
0/2
1734 POINT I/O has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGSegment the control network: isolate the subnet containing 1734 POINT I/O devices from the general IT network and limit connections to engineering workstations and PLCs only
HARDENINGMonitor network traffic to the 1734 POINT I/O for malformed CIP messages; configure IDS/IPS rules to detect and drop packets with invalid CIP structures
API: /api/v1/advisories/bcbc093c-119b-47ed-b62e-61debe1d448b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation 1734 POINT I/O | CVSS 7.5 - OTPulse