The vendor explicitly identifies these products as affected by this CVE.
- EcoStruxure Power Build Rapsody software FR 2.8.1 and prior
- EcoStruxure Power Build Rapsody software INT 2.8.6 and prior
- EcoStruxure Power Build Rapsody software ES 2.8.5 and prior
- EcoStruxure Power Build Rapsody software BEL(NL) 2.8.3 and prior
- EcoStruxure Power Build Rapsody software BEL(FR) 2.8.8 and prior
- Summary
- CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
- Remediation
- Versions FR V2.8.1.0401, INT V2.8.6.200, and ES V2.8.5.0301 of EcoStruxure™ Power Build Rapsody includes a fix for the CVE-2025-13844 vulnerability and is available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309 Please restart the service after installing the new version.
