Stack-based Buffer Overflow in Schneider Electric's Notifier Software
CVE-2025-3916

4.6MEDIUM

What is CVE-2025-3916?

A stack-based buffer overflow vulnerability in Schneider Electric's Notifier Software poses significant security risks. This flaw allows local attackers to craft malicious project files (specifically SSD files) that, when opened by an end user, could lead to arbitrary code execution on the user's system. If exploited, the attacker could gain unauthorized access and control over the affected system. Users are urged to exercise caution and ensure that their software is updated to mitigate potential security threats.

Affected Version(s)

EcoStruxure™ Power Build Rapsody software v2.7.12 FR and prior

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.