Impact
A stack-based buffer overflow exists in the NetStaX EtherNet/IP Stack for releases before version 5.6.1. The overflow can be triggered by a large Class 3 explicit‑message request that is processed on the application side without generating an error or warning, allowing an attacker to corrupt memory and potentially crash the device or achieve remote code execution. The vulnerability aligns with CWE‑121, which describes stack-based buffer overflows where data overruns a buffer.
Affected Systems
The affected products are all of Pyramid Solutions’ EtherNet/IP stacks, including the EtherNet/IP Adapter DLL Kit (EIPA), the EtherNet/IP Adapter DLL Kit with CIP Security (EIPA‑SECURE), the EtherNet/IP Adapter Development Kit (EADK), the EtherNet/IP Adapter Development Kit with CIP Security (EADK‑SECURE), the EtherNet/IP Scanner DLL Kit (EIPS), the EtherNet/IP Scanner DLL Kit with CIP Security (EIPS‑SECURE), the EtherNet/IP Scanner Development Kit (ESDK), and the EtherNet/IP Scanner Development Kit with CIP Security (ESDK‑SECURE). All versions prior to v5.6.1 are affected; the latest release that removes the flaw is NetStaX v5.6.1.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical level of risk. Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the nature of the flaw—exploitable over the network without generating an error—poses a high likelihood of successful attacks in environments where the stack is exposed to untrusted traffic. The likely attack vector is an adversary sending oversized Class 3 explicit messages to an exposed EtherNet/IP endpoint, potentially achieving remote code execution or causing denial of service through device crashes.
OpenCVE Enrichment