CVE-2025-13844

Severity CVSS v4.0:
HIGH
Type:
CWE-415 Double Free
Publication date:
15/01/2026
Last modified:
03/03/2026

Description

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:fr:*:*:* 2.8.1 (including)
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:bel_nl:*:*:* 2.8.3 (including)
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:es:*:*:* 2.8.5 (including)
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:int:*:*:* 2.8.6 (including)
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:bel_fr:*:*:* 2.8.8 (including)