{"id":"CVE-2025-13844","title":"CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.","summary":"CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","cwe":["CWE-415"],"vendor":"schneider-electric","product":"ecostruxure_power_build_-_rapsody","affected":["ecostruxure_power_build_-_rapsody <= 2.8.1","ecostruxure_power_build_-_rapsody <= 2.8.3","ecostruxure_power_build_-_rapsody <= 2.8.5","ecostruxure_power_build_-_rapsody <= 2.8.6","ecostruxure_power_build_-_rapsody <= 2.8.8"],"published":"2026-01-15","updated":"2026-09-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13844","references":[{"url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf","label":"cybersecurity@se.com"}],"tags":["nvd"],"epss":0.0016,"epssPercentile":0.0558,"ingestedAt":"2026-09-03T03:55:24.249Z","slug":"CVE-2025-13844","body":"## Overview\n\nCWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.\n\n## Affected\n\n- `ecostruxure_power_build_-_rapsody <= 2.8.1`\n- `ecostruxure_power_build_-_rapsody <= 2.8.3`\n- `ecostruxure_power_build_-_rapsody <= 2.8.5`\n- `ecostruxure_power_build_-_rapsody <= 2.8.6`\n- `ecostruxure_power_build_-_rapsody <= 2.8.8`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}