Pyramid Solutions NetStaX EtherNet/IP Stack
CISA flags critical CVE-2026-78012 (CVSS 9.8) stack buffer overflow in Pyramid Solutions NetStaX EtherNet/IP stacks below v5.6.1, risking crashes or remote attack vectors.
CISA republished Pyramid Solutions' advisory for CVE-2026-78012, a CWE-121 stack-based buffer overflow in the NetStaX EtherNet/IP stack versions prior to 5.6.1, scored CVSS 9.8. Large Class 3 explicit-message requests can exceed the application-side receive buffer without generating a CIP error, potentially causing memory corruption, device crashes, or a silent remote attack vector. All eight adapter and scanner DLL/development kit variants, including CIP Security editions, are affected across critical manufacturing, energy, water, and chemical sectors. No public exploitation has been reported.
- CVE-2026-78012 (CVSS 9.8) is a stack-based buffer overflow in NetStaX below 5.6.1
- Oversized Class 3 explicit messages overflow the receive buffer without a CIP error
- May cause memory corruption, device crashes, or a silent remote attack vector
- All eight kit variants, including CIP Security editions, are affected; upgrade to 5.6.1+
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-78012 | Stack buffer overflow in Pyramid Solutions NetStaX EtherNet/IP Stack Pyramid Solutions NetStaX EtherNet/IP Stack, versions prior to 5.6.1, fails to reject oversized Class 3 explicit-message requests, allowing them to exceed the application-side receive buffer without generating an error or warning. A remote attacker with network reachability to a device's EtherNet/IP explicit-message interface (typically TCP/44818) can trigger the flaw by sending an oversized request, with no authentication or user interaction required. The result is memory corruption — a stack buffer overflow per CWE-121 — that can crash the device and, per the 9.3 critical CVSS 4.0 score, may also provide a remote attack vector with high confidentiality, integrity, and availability impact on the vulnerable component. Affected parties are industrial device OEMs that license the NetStaX stack and the operators of equipment built with affected versions; the data does not enumerate specific downstream products. No public proof of concept is known, the flaw is not in CISA's KEV, and EPSS assigns only a 0.5% 30-day exploitation probability, indicating no known exploitation to date. Do: Integrators should rebuild their devices with NetStaX EtherNet/IP Stack v5.6.1 or later, and operators of affected equipment should obtain firmware updates from their device vendors, since patch availability depends on each OEM's release cycle. As an interim mitigation, restrict EtherNet/IP explicit messaging (TCP/44818) to trusted OT network segments and keep affected devices off the internet. When inventorying, ask equipment vendors whether their devices use the NetStaX stack and which version they ship. | 9.3 | <1% |
| large≈ tens of thousands of embedded industrial devices (estimate; licensee device counts are undisclosed) |
Full article599 words · extracted from cisa.gov · click to collapse
Summary
Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected:
- EtherNet/IP Adapter DLL Kit (EIPA)
- EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)
- EtherNet/IP Adapter Development Kit (EADK)
- EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)
- EtherNet/IP Scanner DLL Kit (EIPS)
- EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)
- EtherNet/IP Scanner Development Kit (ESDK)
- EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|---|---|---|
| v3 9.8 | Pyramid Solutions | Pyramid Solutions NetStaX EtherNet/IP Stack | Stack-based Buffer Overflow |
Background
- Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United States
Vulnerabilities
CVE-2026-78012
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
Affected Products
Pyramid Solutions NetStaX EtherNet/IP Stack
Vendor:
Pyramid Solutions
Product Version:
Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA): <v5.6.1, Pyramid Solutions EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE): <v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit (EADK): <v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE): <v5.6.1, Pyramid Solutions EtherNet/IP Scanner DLL Kit (EIPS): <v5.6.1, Pyramid Solutions EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE): <v5.6.1, Pyramid Solutions EtherNet/IP Scanner Development Kit (ESDK): <v5.6.1, Pyramid Solutions EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE): <v5.6.1
Product Status:
known_affected
Relevant CWE: CWE-121 Stack-based Buffer Overflow
Metrics
| CVSS Version | Base Score | Base Severity | Vector String |
|---|---|---|---|
| 3.1 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 4.0 | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Acknowledgments
- Pyramid Solutions reported this vulnerability to CISA
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-03
| Date | Revision | Summary |
|---|---|---|
| 2026-09-03 | 1 | Initial Republication of Pyramid Solutions blog publication. |
Legal Notice and Terms of Use
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-07