Rapsody DF: Heap Corruption via malicious SSD import
CVE-2025-13844 Published on January 15, 2026

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

NVD

Weakness Type

What is a Double-free Vulnerability?

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations. When a program calls free() twice with the same argument, the program's memory management data structures become corrupted. This corruption can cause the program to crash or, in some circumstances, cause two later calls to malloc() to return the same pointer. If malloc() returns the same value twice and the program later gives the attacker control over the data that is written into this doubly-allocated memory, the program becomes vulnerable to a buffer overflow attack.

CVE-2025-13844 has been classified to as a Double-free vulnerability or weakness.


Products Associated with CVE-2025-13844

Want to know whenever a new CVE is published for Schneider Electric Ecostruxure Power Build Rapsody? stack.watch will email you.

 

Affected Versions

Schneider Electric EcoStruxure Power Build Rapsody:

Exploit Probability

EPSS
0.01%
Percentile
0.32%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.