CVE-2025-13845
published 2026-01-15CVE-2025-13845: CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.31%
22.4th percentile
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.1.0300 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.2.0000 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.3.0100 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.4.0300 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.5.0200 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.7.0100 | — |
| schneider-electric | ecostruxure_power_build_rapsody | <= 2.8.8.0100 | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
| schneider_electric | ecostruxure_power_build_rapsody | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.08.4HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q993-4v6g-m56m: CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Raps
ghsa_unreviewed·2026-01-15
CVE-2025-13845 [HIGH] CWE-416 GHSA-q993-4v6g-m56m: CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Raps
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
CISA ICS
Schneider Electric EcoStruxure Power Build Rapsody (Update A)
cisa_ics·2026-03-17·CVSS 5.3
[MEDIUM] Schneider Electric EcoStruxure Power Build Rapsody (Update A)
ICS Advisory
##
Schneider Electric EcoStruxure Power Build Rapsody (Update A)
Last RevisedMarch 17, 2026
Alert CodeICSA-26-015-10
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Schneider Electric is aware of a vulnerability in its EcoStruxure Power Build Rapsody software. The [EcoStruxure Power Build Rapsody](https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309) is used to enter or import the single line diagram, to get the extensive bill of material of your switchboard, including all devices, connection items, and mounting components. Failure to apply the mitigations/remediations provided below may risk memory corruption, heap-based buffer overflow, stack-based buf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-01-15
Published