Pyramid Solutions NetStaX EtherNet/IP Stack
September 3, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE) EtherNet/IP Scanner DLL Kit (EIPS) EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE) EtherNet/IP Scanner Development Kit (ESDK) EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE) CVSS Vendor Equipment Vulnerabilities v3 9.8 Pyramid Solutions Pyramid Solutions NetStaX EtherNet/IP Stack Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-78012 An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. View CVE Details Affected Products Pyramid Solutions NetStaX EtherNet/IP Stack Vendor:Pyramid Solutions Product Version:Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA): <v5.6.1, Pyramid Solutions EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE): <v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit (EADK): <v5.6.1, Pyramid Solutions EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE): <v5.6.1, Pyramid...
Key Takeaways
- CISA published an advisory for Pyramid Solutions NetStaX EtherNet/IP Stack urging users to apply vendor patches and mitigations.
- Organizations using Pyramid Solutions NetStaX EtherNet/IP Stack should review CISA's advisory and apply security updates promptly.
- Active exploitation of vulnerabilities in Pyramid Solutions NetStaX EtherNet/IP Stack has been reported, making patching urgent for affected organizations.