criticalZero-Day

Pyramid Solutions NetStaX EtherNet/IP Stack Stack-based Buffer Overflow (CVE-2026-78012)

First seen Sep 5, 2026 · Updated Sep 5, 2026 · CVSS 9.8

icsotethernet-ipcipbuffer-overflowcritical-infrastructurecisa-advisory

A critical stack-based buffer overflow vulnerability affects Pyramid Solutions NetStaX EtherNet/IP Stack products prior to v5.6.1, used across industrial control system (ICS) devices. Exploitation via oversized Class 3 explicit-message requests could cause memory corruption, device crashes, or remote code execution without any CIP error notification, posing significant risk to critical manufacturing, energy, water, and chemical sectors.

Technical Analysis

CVE-2026-78012 (CVSS 3.1: 9.8 Critical, CVSS 4.0: 9.3 Critical) is a CWE-121 stack-based buffer overflow in NetStaX EtherNet/IP Stack versions prior to 5.6.1, affecting EIPA, EIPA-SECURE, EADK, EADK-SECURE, EIPS, EIPS-SECURE, ESDK, and ESDK-SECURE product lines. The flaw arises when a large Class 3 explicit-message request exceeds the application-side receive buffer without triggering an error or warning, enabling an unauthenticated remote attacker (AV:N/AC:L/PR:N/UI:N) to corrupt memory, crash the device, or potentially achieve remote code execution. This is a firmware/embedded stack vulnerability affecting OT/ICS network protocol handling rather than IT/enterprise software, and there is no plausible direct impact to AI agent systems, LLM tool use, or RAG pipelines. Vendor remediation (v5.6.1) adds compile-time assertions, runtime payload-size checks, and improved buffer-size documentation; no public exploitation has been reported to CISA at this time.

Affected Systems

Pyramid Solutions NetStaX EtherNet/IP Stack products prior to v5.6.1: EtherNet/IP Adapter DLL Kit (EIPA), EIPA-SECURE, EtherNet/IP Adapter Development Kit (EADK), EADK-SECURE, EtherNet/IP Scanner DLL Kit (EIPS), EIPS-SECURE, EtherNet/IP Scanner Development Kit (ESDK), ESDK-SECURE — deployed worldwide in critical manufacturing, energy, water/wastewater, and chemical sector devices.

Indicators of Compromise

  • No known IOCs; no public exploitation reported at time of advisory.

Remediation Steps

  1. 1

    Upgrade to NetStaX v5.6.1

    Update all affected EtherNet/IP Adapter and Scanner DLL/Development Kits to version 5.6.1 or later, which adds compile-time assertions and runtime payload-size checks to prevent the overflow.

  2. 2

    Isolate ICS networks

    Minimize network exposure for all control system devices; ensure they are not accessible from the internet and are located behind firewalls, segmented from business networks.

  3. 3

    Secure remote access

    Use up-to-date VPNs for any required remote access to control system networks, recognizing that VPN security depends on the security of connected devices.

  4. 4

    Monitor and report

    Follow internal security procedures to monitor for anomalous CIP explicit-message traffic and report suspected malicious activity to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-78012

Industries Most Exposed

Critical ManufacturingEnergyWater and WastewaterChemical

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.