CVE-2025-13845

EUVD-2026-2706
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
schneider-electricecostruxure_power_build_-_rapsody
𝑥
≤ 2.8.1.0300
schneider-electricecostruxure_power_build_-_rapsody
𝑥
≤ 2.8.2.0000
schneider-electricecostruxure_power_build_-_rapsody
𝑥
≤ 2.8.3.0100
schneider-electricecostruxure_power_build_-_rapsody
𝑥
≤ 2.8.4.0300
schneider-electricecostruxure_power_build_-_rapsody
𝑥
≤ 2.8.5.0200
schneider-electricecostruxure_power_build_-_rapsody
𝑥
≤ 2.8.7.0100
schneider-electricecostruxure_power_build_-_rapsody
𝑥
≤ 2.8.8.0100
𝑥
= Vulnerable software versions