Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected:
EtherNet/IP Adapter DLL Kit (EIPA)
EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE)
EtherNet/IP Adapter Development Kit (EADK)
EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE)
EtherNet/IP Scanner DLL Kit (EIPS)
EtherNet/IP Scanner DLL Kit with CIP Security (EIPS-SECURE)
EtherNet/IP Scanner Development Kit (ESDK)
EtherNet/IP Scanner Development Kit with CIP Security (ESDK-SECURE)
Vendor
Equipment
Pyramid Solutions
Pyramid Solutions NetStaX EtherNet/IP Stack
Stack-based Buffer Overflow
Critical Infrastructure Sectors: Critical...
Read the full advisory on CISA →