CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ecostruxure_power_build_-_rapsody | Schneider-electric | * | 2.8.1 (including) |
| Ecostruxure_power_build_-_rapsody | Schneider-electric | * | 2.8.3 (including) |
| Ecostruxure_power_build_-_rapsody | Schneider-electric | * | 2.8.5 (including) |
| Ecostruxure_power_build_-_rapsody | Schneider-electric | * | 2.8.6 (including) |
| Ecostruxure_power_build_-_rapsody | Schneider-electric | * | 2.8.8 (including) |