Pyramid Solutions NetStaX EtherNet/IP Stack

Plan PatchCVSS 9.8ICS-CERT ICSA-26-246-07Sep 3, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A buffer overflow vulnerability in Pyramid Solutions NetStaX EtherNet/IP stack (versions prior to 5.6.1) allows an attacker to send a crafted EtherNet/IP explicit message with an oversized payload that bypasses payload-size validation. This can result in memory corruption, device crash, or potential remote code execution. The receiving device may not generate a CIP error, allowing the attack to occur silently. The vulnerability affects all variants of the EtherNet/IP Adapter and Scanner DLL and Development Kits (EIPA, EADK, EIPS, ESDK and their CIP Security versions). NetStaX v5.6.1 addresses the issue with compile-time assertions, runtime payload-size checks, and improved documentation.

What this means
What could happen
An attacker could send a crafted EtherNet/IP message to cause memory corruption or crash a device running the vulnerable NetStaX stack, potentially disrupting automation control or data collection without any error indication to the receiving device.
Who's at risk
This vulnerability affects any industrial devices or software using Pyramid Solutions NetStaX libraries for EtherNet/IP communication, including PLCs, remote I/O devices, drives, sensors, and custom automation applications that implement the adapter or scanner kits. Water treatment facilities, electric utilities, and manufacturing plants using EtherNet/IP-based equipment are directly impacted.
How it could be exploited
An attacker sends a malformed EtherNet/IP explicit message with an oversized payload to a device running the vulnerable NetStaX library. The stack fails to validate the payload size, causing a buffer overflow that corrupts memory, crashes the process, or in some cases may allow arbitrary code execution.
Prerequisites
  • Network access to the EtherNet/IP port (typically UDP 2222 or TCP 2222)
  • Device or application running NetStaX DLL or SDK version prior to 5.6.1
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)affects automation control devices
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (8)
8 pending
ProductAffected VersionsFix Status
EtherNet/IP Adapter DLL Kit (EIPA)<v5.6.1No fix yet
EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)<v5.6.1No fix yet
EtherNet/IP Adapter Development Kit (EADK)<v5.6.1No fix yet
EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)<v5.6.1No fix yet
EtherNet/IP Scanner DLL Kit (EIPS)<v5.6.1No fix yet
EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)<v5.6.1No fix yet
EtherNet/IP Scanner Development Kit (ESDK)<v5.6.1No fix yet
EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)<v5.6.1No fix yet
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict EtherNet/IP network access (TCP/UDP port 2222) to only authorized control devices and engineering workstations using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

EtherNet/IP Adapter DLL Kit (EIPA)
HOTFIXUpdate all NetStaX libraries (EIPA, EADK, EIPS, ESDK and their CIP Security variants) to version 5.6.1 or later
Long-term hardening
0/2
HARDENINGImplement network segmentation to isolate EtherNet/IP automation networks from untrusted networks and the Internet
HARDENINGMonitor EtherNet/IP traffic for abnormally large or malformed explicit messages that could indicate exploitation attempts
API: /api/v1/advisories/5116b5df-73f6-49b1-917e-307231781b42

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.