CVE-2025-13844
published 2026-01-15CVE-2025-13844: CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the…
high8.4CVSS 4.0
AVLACLATNPRNUIAVCHVIHVAHSCLSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.1 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.3 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.5 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.6 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.8 | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |