CVE-2026-78012

9.8

Pyramid Solutions · NetStaX EtherNet/IP Stack

A buffer overflow vulnerability in the NetStaX EtherNet/IP Stack allows unauthenticated remote attackers to cause memory corruption or device crashes via malformed Class 3 explicit-message requests.

Executive summary

The Pyramid Solutions NetStaX EtherNet/IP Stack contains a critical buffer overflow vulnerability that allows unauthenticated remote attackers to trigger memory corruption or system crashes.

Vulnerability

This is a stack-based buffer overflow (CWE-121) occurring when the application fails to validate the size of Class 3 explicit-message requests, allowing an unauthenticated remote attacker to exceed buffer limits without triggering error logs.

Business impact

The ability for an unauthenticated attacker to remotely corrupt memory or crash industrial communication stacks poses a significant risk to operational technology environments. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it could lead to unauthorized system disruption, loss of process control, and potential safety implications if the affected devices are controlling industrial machinery.

Remediation

Immediate Action: Update all affected components, including the EIPA, EIPA-SECURE, EADK, EADK-SECURE, EIPS, and EIPS-SECURE kits, to version 5.6.1 or later.

Proactive Monitoring: Monitor network traffic for unusually large Class 3 explicit-message requests and review device logs for unexpected resets or communication timeouts indicative of crash attempts.

Compensating Controls: Deploy industrial firewalls or deep packet inspection (DPI) solutions configured to restrict EtherNet/IP traffic and validate the structure of CIP messages before they reach the controller.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and the potential for remote exploitation without authentication, immediate remediation is required. Organizations utilizing the NetStaX stack must prioritize the upgrade to version 5.6.1 to implement the necessary runtime payload-size checks and protect against silent memory corruption.

Sources

Originally found and disclosed by Pyramid Solutions reported this vulnerability to CISA., per the CVE Program record.