The vendor explicitly identifies these products as affected by this CVE.
- EcoStruxure Power Build Rapsody software FR 2.8.1.0300 and prior
- EcoStruxure Power Build Rapsody software ES 2.8.5.0200 and prior
- EcoStruxure Power Build Rapsody software PT 2.8.7.0100 and prior
- EcoStruxure Power Build Rapsody software BEL(FR) 2.8.8.0100 and prior
- EcoStruxure Power Build Rapsody software BEL(EN) 2.8.3.0100 and prior
- EcoStruxure Power Build Rapsody software INT(EN) 2.8.4.0300 and prior
- EcoStruxure Power Build Rapsody software NL 2.8.2.0000 and prior
- Summary
- CWE-416: Use After Free vulnerability exists that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
- Remediation
- Versions FR V2.8.1.0401, ESP V2.8.5.0301, PT V2.8.7.0101, INT(EN) V2.8.4.0401, and NL V2.8.2.000 of EcoStruxure™ Power Build Rapsody includes a fix for the CVE-2025-13845 vulnerability and are available for download here: https://www.se.com/ww/en/product-country-selector/?pageType=product-range&sourceId=2309 Please restart the service after installing the new version.
