CVE-2025-13845

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:fr:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:nl:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:bel_en:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:int_en:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:esp:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:pt:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:bel_fr:*:*:*

History

27 Apr 2026, 17:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf - () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2026-013-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-013-04.pdf - Vendor Advisory
CPE cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:fr:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:int_en:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:bel_en:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:bel_fr:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:nl:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:esp:*:*:*
cpe:2.3:a:schneider-electric:ecostruxure_power_build_-_rapsody:*:*:*:*:pt:*:*:*
Summary
  • (es) CWE-416: Vulnerabilidad Use After Free que podría causar ejecución remota de código cuando el usuario final importa el archivo de proyecto malicioso (archivo SSD) en Rapsody.
First Time Schneider-electric
Schneider-electric ecostruxure Power Build - Rapsody

15 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 19:16

Updated : 2026-04-27 17:26


NVD link : CVE-2025-13845

Mitre link : CVE-2025-13845

CVE.ORG link : CVE-2025-13845


JSON object : View

Products Affected

schneider-electric

  • ecostruxure_power_build_-_rapsody
CWE
CWE-416

Use After Free