Use After Free Vulnerability in Rapsody by Schneider Electric
CVE-2025-13845

8.4HIGH

What is CVE-2025-13845?

A Use After Free vulnerability exists in Rapsody, which may allow an attacker to execute arbitrary code on a user's system when a malicious SSD project file is imported. This issue arises due to improper memory management, which can lead to unexpected application behavior and potential compromise of user systems. Users are encouraged to update their software to mitigate this security risk.

Affected Version(s)

EcoStruxure Power Build Rapsody FR v2.8.1.0300 and prior

EcoStruxure Power Build Rapsody ESP v2.8.5.0200 and prior

EcoStruxure Power Build Rapsody PT v2.8.7.0100 and prior

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.