news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation 1734 POINT I/O

Medium
Summary

Rockwell Automation’s 1734 POINT I/O module is vulnerable to a denial-of-service attack due to improper handling of crafted CIP messages, potentially causing a system fault and requiring a restart. CISA urges organizations to mitigate the risk by upgrading to a corrected version or implementing security best practices. No public exploitation has been reported.

Rockwell Automation’s 1734 POINT I/O module is vulnerable to a denial-of-service attack. The issue stems from a flaw in how the module processes CIP messages, leading to a faulted state and the need for a restart to recover. This vulnerability affects the 1734 POINT I/O 3.023 version. The affected product is used in critical manufacturing sectors worldwide, with Rockwell Automation’s headquarters located in the United States. CISA recommends that organizations take immediate action to mitigate this risk by migrating to a corrected version, specifically 5034-OB8, or by implementing Rockwell Automation’s security best practices, accessible at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight. For more detailed information and additional security advisories, refer to Rockwell Automation’s Trust Center: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html. CISA advises minimizing network exposure for control system devices and isolating them from business networks, utilizing secure remote access methods like VPNs (updated to the latest version), and implementing proactive cybersecurity strategies. Organizations are encouraged to report any suspected malicious activity to CISA.

Read the full article at CISA Advisories