CVE-2025-13844

MEDIUM

Rapsody - Memory Corruption

Title source: llm
STIX 2.1

Description

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-415
Status published
Products (5)
schneider-electric/ecostruxure_power_build_-_rapsody < 2.8.1
schneider-electric/ecostruxure_power_build_-_rapsody < 2.8.3
schneider-electric/ecostruxure_power_build_-_rapsody < 2.8.5
schneider-electric/ecostruxure_power_build_-_rapsody < 2.8.6
schneider-electric/ecostruxure_power_build_-_rapsody < 2.8.8
Published Jan 15, 2026
Tracked Since Feb 18, 2026