Impact
A denial‑of‑service vulnerability exists in the 1734 POINT I/O module caused by improper handling of crafted CIP messages. The fault can be triggered when the module processes maliciously formed CIP packets, leading the device to enter a faulted state. Once faulted, the module cannot process legitimate traffic until it is manually restarted. The issue results in a loss of availability for any system or process relying on the 1734 POINT I/O module. It represents a resource exhaustion weakness (CWE‑770) with no direct impact on confidentiality or integrity.
Affected Systems
Rockwell Automation’s 1734 POINT I/O™ module is affected. The advisory does not specify affected firmware or hardware revisions; therefore all firmware versions of the 1734 POINT I/O module remain vulnerable until a vendor patch is applied.
Risk and Exploitability
The vulnerability scores a CVSS of 8.7, indicating a high‑severity threat to availability. The EPSS score is less than 1 %, suggesting that, although possible, exploitation is unlikely to occur in the wild at this time, ISA’s KEV catalog. Attackers would need network access to the CIP interface and would send specially crafted CIP packets to trigger the fault. No local privilege escalation or remote code execution is possible; the primary risk is denial of service to the affected module and any dependent systems.
OpenCVE Enrichment