Double Free Vulnerability in Rapsody by Schneider Electric
CVE-2025-13844

8.4HIGH

What is CVE-2025-13844?

A double free vulnerability in Rapsody may lead to heap memory corruption when users import a malicious SSD project file shared by attackers. This flaw can potentially be exploited to manipulate memory allocation, leading to unexpected behavior or system crashes. It is crucial for users to implement security measures to mitigate the risk associated with importing unverified project files.

Affected Version(s)

EcoStruxure Power Build Rapsody FR v2.8.1 and prior

EcoStruxure Power Build Rapsody INT v2.8.6 and prior

EcoStruxure Power Build Rapsody ES v2.8.5 and prior

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.