CVE Vulnerabilities

CVE-2025-13844

Double Free

Published: Jan 15, 2026 | Modified: Mar 03, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Ecostruxure_power_build_-_rapsodySchneider-electric*2.8.1 (including)
Ecostruxure_power_build_-_rapsodySchneider-electric*2.8.3 (including)
Ecostruxure_power_build_-_rapsodySchneider-electric*2.8.5 (including)
Ecostruxure_power_build_-_rapsodySchneider-electric*2.8.6 (including)
Ecostruxure_power_build_-_rapsodySchneider-electric*2.8.8 (including)

Potential Mitigations

References