CVE-2026-78012
9.8Pyramid Solutions · NetStaX EtherNet/IP Stack
A buffer overflow vulnerability in the NetStaX EtherNet/IP Stack allows unauthenticated remote attackers to cause memory corruption or device crashes via malformed Class 3 explicit-message requests.
Executive summary
The Pyramid Solutions NetStaX EtherNet/IP Stack contains a critical buffer overflow vulnerability that allows unauthenticated remote attackers to trigger memory corruption or system crashes.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring when the application fails to validate the size of Class 3 explicit-message requests, allowing an unauthenticated remote attacker to exceed buffer limits without triggering error logs.
Business impact
The ability for an unauthenticated attacker to remotely corrupt memory or crash industrial communication stacks poses a significant risk to operational technology environments. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it could lead to unauthorized system disruption, loss of process control, and potential safety implications if the affected devices are controlling industrial machinery.
Remediation
Immediate Action: Update all affected components, including the EIPA, EIPA-SECURE, EADK, EADK-SECURE, EIPS, and EIPS-SECURE kits, to version 5.6.1 or later.
Proactive Monitoring: Monitor network traffic for unusually large Class 3 explicit-message requests and review device logs for unexpected resets or communication timeouts indicative of crash attempts.
Compensating Controls: Deploy industrial firewalls or deep packet inspection (DPI) solutions configured to restrict EtherNet/IP traffic and validate the structure of CIP messages before they reach the controller.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for remote exploitation without authentication, immediate remediation is required. Organizations utilizing the NetStaX stack must prioritize the upgrade to version 5.6.1 to implement the necessary runtime payload-size checks and protect against silent memory corruption.
Sources
Originally found and disclosed by Pyramid Solutions reported this vulnerability to CISA., per the CVE Program record.