CVE-2026-78012
Stack-based Buffer Overflow in Pyramid Solutions NetStaX EtherNet/IP Stack
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
| CWE | CWE-121 |
| Vendor | pyramid solutions |
| Product | ethernet/ip adapter dll kit (eipa) |
| Published | Sep 1, 2026 |
| Last Updated | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for pyramid solutions ethernet/ip adapter dll kit (eipa)
Be the first to know when new critical vulnerabilities affecting pyramid solutions ethernet/ip adapter dll kit (eipa) are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Pyramid Solutions / EtherNet/IP Adapter DLL Kit (EIPA)
0 ≤ v5.6.1
Pyramid Solutions / EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)
0 ≤ v5.6.1
Pyramid Solutions / EtherNet/IP Adapter Development Kit (EADK)
0 ≤ v5.6.1
Pyramid Solutions / EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)
0 ≤ v5.6.1
Pyramid Solutions / EtherNet/IP Scanner DLL Kit (EIPS)
0 ≤ v5.6.1
Pyramid Solutions / EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)
0 ≤ v5.6.1
Pyramid Solutions / EtherNet/IP Scanner Development Kit (ESDK)
0 ≤ v5.6.1
Pyramid Solutions / EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)
0 < v5.6.1
References
Credits
Pyramid Solutions reported this vulnerability to CISA.