CVE-2025-13844
published 2026-01-15CVE-2025-13844: CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the…
PriorityP424medium5.3CVSS 3.1
AVLACLPRNUIRSUCLILAL
EPSS
0.14%
3.6th percentile
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.1 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.3 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.5 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.6 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.8 | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv4.08.4HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r2h5-jh8m-2q64: CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared
ghsa_unreviewed·2026-01-15
CVE-2025-13844 [HIGH] CWE-415 GHSA-r2h5-jh8m-2q64: CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
CISA ICS
Schneider Electric EcoStruxure Power Build Rapsody (Update A)
cisa_ics·2026-03-17·CVSS 5.3
[MEDIUM] Schneider Electric EcoStruxure Power Build Rapsody (Update A)
ICS Advisory
##
Schneider Electric EcoStruxure Power Build Rapsody (Update A)
Last RevisedMarch 17, 2026
Alert CodeICSA-26-015-10
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Schneider Electric is aware of a vulnerability in its EcoStruxure Power Build Rapsody software. The [EcoStruxure Power Build Rapsody](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309) is used to enter or import the single line diagram, to get the extensive bill of material of your switchboard, including all devices, connection items, and mounting components. Failure to apply the mitigations/remediations provided below may risk memory corruption, heap-based buffer overflow, stack-based buf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-01-15
Published