CVE-2025-13844: Double Free
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13844?
CVE-2025-13844 is classified as a high severity vulnerability due to potential heap memory corruption.
How do I fix CVE-2025-13844?
To fix CVE-2025-13844, update to the latest version of Schneider Electric Ecostruxure Power Build - Rapsody that addresses this vulnerability.
What causes CVE-2025-13844?
CVE-2025-13844 is caused by a double free vulnerability when importing a malicious SSD project file.
Which software versions are affected by CVE-2025-13844?
CVE-2025-13844 affects Schneider Electric Ecostruxure Power Build - Rapsody versions up to 2.8.1, 2.8.3, 2.8.5, 2.8.6, and 2.8.8.
What impacts can CVE-2025-13844 have on users?
CVE-2025-13844 can lead to application crashes or arbitrary code execution, putting user data and system integrity at risk.