CVE-2025-3916 Details
Description
CWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentially execute arbitrary code while the end user opens a malicious project file (SSD file) provided by the attacker.
A stack-based buffer overflow vulnerability has been identified in Schneider Electric's EcoStruxure Power Build Rapsody software, specifically in versions through 2.7.12 FR. This vulnerability could allow local attackers to execute arbitrary code by exploiting memory corruption issues. The vulnerability is triggered when a user opens a malicious project file (SSD file) provided by the attacker.
Users can upgrade to version 2.8.1 FR of EcoStruxure Power Build Rapsody, which includes a fix for this vulnerability. After installing the new version, a reboot is recommended. For those who choose not to apply the update, it is advised to store project files securely, restrict access to trusted users, use secure communication protocols when exchanging files, encrypt project files, verify the integrity of project files before use, and harden the workstation running the software.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2025CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Schneider Electric EcoStruxure Power Build Rapsody | <= 2.7.12 FR |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2025 | New CVE Received | [email protected] |
Volerion