Pyramid NetStaX Flaw Hides a Crash Behind Valid Traffic

CISA issued an advisory for CVE-2026-78012 in Pyramid Solutions’ NetStaX EtherNet/IP Stack, saying oversized Class 3 explicit messages can slip past the receive buffer in eight affected adapter and scanner kits before the stack raises any CIP error. The affected builds include both DLL and development kits, with and without CIP Security, and they are used in critical manufacturing, energy, water and wastewater, and chemical environments. In plain terms, the stack is supposed to reject a message that is too big for the application buffer, but this flaw lets the request run on anyway. That can corrupt memory, crash a device, or leave open a remote attack vector, while the normal protocol-level rejection never appears to alert operators or tooling. For industrial estates that rely on NetStaX-based adapters or scanners, the exposure sits in the communication layer itself: devices may fail before they look like they received a bad packet. If these kits are in service, the concern is not just one library version but any product line built on top of it that inherits the same silent overflow behavior.

Part of the PlainSec briefing for 2026-09-03

Every edition of this story: Pyramid NetStaX Flaw Hides a Crash Behind Valid Traffic

Sources