Pyramid Solutions NetStaX EtherNet/IP Stack
A buffer overflow vulnerability in Pyramid Solutions NetStaX EtherNet/IP stack (versions prior to 5.6.1) allows an attacker to send a crafted EtherNet/IP explicit message with an oversized payload that bypasses payload-size validation. This can result in memory corruption, device crash, or potential remote code execution. The receiving device may not generate a CIP error, allowing the attack to occur silently. The vulnerability affects all variants of the EtherNet/IP Adapter and Scanner DLL and Development Kits (EIPA, EADK, EIPS, ESDK and their CIP Security versions). NetStaX v5.6.1 addresses the issue with compile-time assertions, runtime payload-size checks, and improved documentation.
- Network access to the EtherNet/IP port (typically UDP 2222 or TCP 2222)
- Device or application running NetStaX DLL or SDK version prior to 5.6.1
Patching may require device reboot — plan for process interruption
/api/v1/advisories/5116b5df-73f6-49b1-917e-307231781b42Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.