---
id: CVE-2025-13845
title: >-
  CWE-416: Use After Free vulnerability that could cause remote code execution
  when the end user imports the malicious project file (SSD file) into Rapsody.
summary: >-
  CWE-416: Use After Free vulnerability that could cause remote code execution
  when the end user imports the malicious project file (SSD file) into Rapsody.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: schneider-electric
product: ecostruxure_power_build_-_rapsody
affected:
  - ecostruxure_power_build_-_rapsody <= 2.8.1.0300
  - ecostruxure_power_build_-_rapsody <= 2.8.2.0000
  - ecostruxure_power_build_-_rapsody <= 2.8.3.0100
  - ecostruxure_power_build_-_rapsody <= 2.8.4.0300
  - ecostruxure_power_build_-_rapsody <= 2.8.5.0200
  - ecostruxure_power_build_-_rapsody <= 2.8.7.0100
  - ecostruxure_power_build_-_rapsody <= 2.8.8.0100
published: '2026-01-15'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13845'
references:
  - url: >-
      https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf
    label: cybersecurity@se.com
tags:
  - nvd
epss: 0.00353
epssPercentile: 0.29053
ingestedAt: '2026-09-03T03:55:24.291Z'
---

## Overview

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

## Affected

- `ecostruxure_power_build_-_rapsody <= 2.8.1.0300`
- `ecostruxure_power_build_-_rapsody <= 2.8.2.0000`
- `ecostruxure_power_build_-_rapsody <= 2.8.3.0100`
- `ecostruxure_power_build_-_rapsody <= 2.8.4.0300`
- `ecostruxure_power_build_-_rapsody <= 2.8.5.0200`
- `ecostruxure_power_build_-_rapsody <= 2.8.7.0100`
- `ecostruxure_power_build_-_rapsody <= 2.8.8.0100`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
