CVE-2025-13844
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2026-01-15
Last updated on: 2026-03-03
Assigner: Schneider Electric SE
Description
Description
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| schneider-electric | ecostruxure_power_build_-_rapsody | to 2.8.8 (inc) |
| schneider-electric | ecostruxure_power_build_-_rapsody | to 2.8.3 (inc) |
| schneider-electric | ecostruxure_power_build_-_rapsody | to 2.8.5 (inc) |
| schneider-electric | ecostruxure_power_build_-_rapsody | to 2.8.1 (inc) |
| schneider-electric | ecostruxure_power_build_-_rapsody | to 2.8.6 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-415 | The product calls free() twice on the same memory address. |