ZeroHour

CVE-2026-78012

large

Stack buffer overflow in Pyramid Solutions NetStaX EtherNet/IP Stack

CVSS 4.0
9.3 critical
EPSS
<1%p40
Published
()
Modified
AI analysis

Pyramid Solutions NetStaX EtherNet/IP Stack, versions prior to 5.6.1, fails to reject oversized Class 3 explicit-message requests, allowing them to exceed the application-side receive buffer without generating an error or warning. A remote attacker with network reachability to a device's EtherNet/IP explicit-message interface (typically TCP/44818) can trigger the flaw by sending an oversized request, with no authentication or user interaction required. The result is memory corruption — a stack buffer overflow per CWE-121 — that can crash the device and, per the 9.3 critical CVSS 4.0 score, may also provide a remote attack vector with high confidentiality, integrity, and availability impact on the vulnerable component. Affected parties are industrial device OEMs that license the NetStaX stack and the operators of equipment built with affected versions; the data does not enumerate specific downstream products. No public proof of concept is known, the flaw is not in CISA's KEV, and EPSS assigns only a 0.5% 30-day exploitation probability, indicating no known exploitation to date.

What to do: Integrators should rebuild their devices with NetStaX EtherNet/IP Stack v5.6.1 or later, and operators of affected equipment should obtain firmware updates from their device vendors, since patch availability depends on each OEM's release cycle. As an interim mitigation, restrict EtherNet/IP explicit messaging (TCP/44818) to trusted OT network segments and keep affected devices off the internet. When inventorying, ask equipment vendors whether their devices use the NetStaX stack and which version they ship.

Affected
Pyramid Solutions NetStaX EtherNet/IP Stackprior to v5.6.1 (< 5.6.1)
Estimated exposure
large≈ tens of thousands of embedded industrial devices (estimate; licensee device counts are undisclosed) — No install or licensee counts are published; this is estimated from public internet scans showing hundreds of thousands of EtherNet/IP endpoints on TCP/44818, assuming only a minority of exposed industrial devices embed this particular…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

Weakness
CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Pyramid Solutions NetStaX EtherNet/IP Stack

CISA flags critical CVE-2026-78012 (CVSS 9.8) stack buffer overflow in Pyramid Solutions NetStaX EtherNet/IP stacks below v5.6.1, risking crashes or remote attack vectors.

CISA republished Pyramid Solutions' advisory for CVE-2026-78012, a CWE-121 stack-based buffer overflow in the NetStaX EtherNet/IP stack versions prior to 5.6.1, scored CVSS 9.8. Large Class 3 explicit-message requests can exceed the application-side receive buffer without generating a CIP error, potentially causing memory corruption, device crashes, or a silent remote attack vector. All eight adapter and scanner DLL/development kit variants, including CIP Security editions, are affected across critical manufacturing, energy, water, and chemical sectors. No public exploitation has been reported.

CISA Advisories · 12d agoAdvisoryCVE-2026-78012