Home

Description

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

PUBLISHED Reserved 2025-12-01 | Published 2026-01-15 | Updated 2026-01-15 | Assigner schneider




HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-416 Use After Free

Product status

Default status
unaffected

FR v2.8.1.0300 and prior
affected

ESP v2.8.5.0200 and prior
affected

PT v2.8.7.0100 and prior
affected

BEL (FR) v2.8.8.0100 and prior
affected

BEL (EN) v2.8.3.0100 and prior
affected

INT (EN) v2.8.4.0300 and prior
affected

NL v2.8.2.0000 and prior
affected

References

download.schneider-electric.com/...Name=SEVD-2026-013-04.pdf

cve.org (CVE-2025-13845)

nvd.nist.gov (CVE-2025-13845)

Download JSON