Pyramid Solutions NetStaX EtherNet/IP Stack
A critical vulnerability exists in Pyramid Solutions NetStaX EtherNet/IP Stack versions prior to 5.6.1, potentially leading to memory corruption and a remote attack vector without triggering a CIP error. This could impact critical infrastructure sectors like manufacturing, energy, and water/wastewater. Users are advised to upgrade to version 5.6.1 or implement mitigation strategies to reduce the risk of exploitation.
A critical vulnerability has been identified in Pyramid Solutions NetStaX EtherNet/IP Stack. Versions prior to 5.6.1 are susceptible to a buffer overflow issue, where a large Class 3 explicit-message request can exceed the application-side receive buffer without generating an error. This could result in memory corruption, device crashes, or a potential remote attack vector. The vulnerability is actively being tracked by CISA.
Affected Products: Pyramid Solutions NetStaX EtherNet/IP Stack, Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA), Pyramid Solutions EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE), Pyramid Solutions EtherNet/IP Adapter Development Kit (EADK), Pyramid Solutions EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE), Pyramid Solutions EtherNet/IP Scanner DLL Kit (EIPS), Pyramid Solutions EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE), Pyramid Solutions EtherNet/IP Scanner Development Kit (ESDK), Pyramid Solutions EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE).
CISA recommends that users immediately upgrade to version 5.6.1 or implement mitigation strategies to address this vulnerability. These include minimizing network exposure for control system devices, isolating them behind firewalls, and utilizing secure remote access methods like VPNs (while recognizing VPN vulnerabilities). Organizations are encouraged to perform thorough impact analysis and risk assessments before deploying any defensive measures and to report any suspected malicious activity to CISA.