← Terug naar overzicht

A vulnerability in the NetStaX EtherNet/IP Stack prior to version 5.6.1 allows a large Class 3 explicit-message request to silently overflow the application-side receive buffer. The flaw is particularly dangerous because no error or warning is generated, meaning the originating device receives no CIP error indicating the request failed. Potential consequences include memory corruption, device crashes, and exploitation as a remote attack vector. The vulnerability affects industrial control system components using the EtherNet/IP protocol stack developed by Pyramid Solutions. The issue is silently exploitable, increasing risk in operational technology (OT) environments. A fix has been issued in NetStaX version 5.6.1. This type of vulnerability is especially concerning in critical infrastructure contexts where reliability and availability are paramount.

Affected products

  • NetStaX EtherNet/IP Stack

Related CVE's

  • CVE-2026-78012

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure