---
id: CVE-2025-13844
title: >-
  CWE-415: Double Free vulnerability exists that could cause heap memory
  corruption when the end user imports a malicious project file (SSD file)
  shared by the attacker into Rapsody.
summary: >-
  CWE-415: Double Free vulnerability exists that could cause heap memory
  corruption when the end user imports a malicious project file (SSD file)
  shared by the attacker into Rapsody.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-415
vendor: schneider-electric
product: ecostruxure_power_build_-_rapsody
affected:
  - ecostruxure_power_build_-_rapsody <= 2.8.1
  - ecostruxure_power_build_-_rapsody <= 2.8.3
  - ecostruxure_power_build_-_rapsody <= 2.8.5
  - ecostruxure_power_build_-_rapsody <= 2.8.6
  - ecostruxure_power_build_-_rapsody <= 2.8.8
published: '2026-01-15'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13844'
references:
  - url: >-
      https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf
    label: cybersecurity@se.com
tags:
  - nvd
epss: 0.0016
epssPercentile: 0.05582
ingestedAt: '2026-09-03T03:55:24.249Z'
---

## Overview

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

## Affected

- `ecostruxure_power_build_-_rapsody <= 2.8.1`
- `ecostruxure_power_build_-_rapsody <= 2.8.3`
- `ecostruxure_power_build_-_rapsody <= 2.8.5`
- `ecostruxure_power_build_-_rapsody <= 2.8.6`
- `ecostruxure_power_build_-_rapsody <= 2.8.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
