CVE-2025-13844: Schneider Electric Ecostruxure Power Build - Rapsody

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

Affected products

  • Schneider Electric Ecostruxure Power Build - Rapsody: up to and including 2.8.1; up to and including 2.8.3; up to and including 2.8.5; up to and including 2.8.6; up to and including 2.8.8

Published 2026-01-15. Last modified 2026-09-03.