CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Pyramid Solutions NetStaX EtherNet/IP Stack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5658

As cited

Copy frozen at (site build).

vulnerabilities

Pyramid Solutions NetStaX EtherNet/IP Stack

A stack-based buffer overflow in Pyramid Solutions NetStaX EtherNet/IP Stack versions prior to 5.6.1 allows large Class 3 explicit-message requests to bypass receive buffer validation. Exploitation could cause memory corruption, device crashes, or remote attacks without triggering error notifications. The vulnerability (CVE-2026-78012, CVSS 9.3) affects eight variants of the EtherNet/IP adapter and scanner toolkits used across manufacturing, energy, water, and chemical sectors worldwide.

Why it matters: Organizations deploying NetStaX EtherNet/IP Stack in operational technology environments must upgrade to version 5.6.1 immediately, as this network-accessible vulnerability requires no authentication and can silently compromise critical infrastructure devices across multiple sectors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Pyramid Solutions NetStaX EtherNet/IP Stack

A stack-based buffer overflow in Pyramid Solutions NetStaX EtherNet/IP Stack versions prior to 5.6.1 allows large Class 3 explicit-message requests to bypass receive buffer validation. Exploitation could cause memory corruption, device crashes, or remote attacks without triggering error notifications. The vulnerability (CVE-2026-78012, CVSS 9.3) affects eight variants of the EtherNet/IP adapter and scanner toolkits used across manufacturing, energy, water, and chemical sectors worldwide.

Why it matters: Organizations deploying NetStaX EtherNet/IP Stack in operational technology environments must upgrade to version 5.6.1 immediately, as this network-accessible vulnerability requires no authentication and can silently compromise critical infrastructure devices across multiple sectors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary