Schneider Electric EcoStruxure Power Build Rapsody Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Schneider Electric's EcoStruxure Power Build Rapsody software, specifically in versions through 2.7.12 FR. This vulnerability could allow local attackers to execute arbitrary code by exploiting memory corruption issues. The vulnerability is triggered when a user opens a malicious project file (SSD file) provided by the attacker.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.

Remediation

Users can upgrade to version 2.8.1 FR of EcoStruxure Power Build Rapsody, which includes a fix for this vulnerability. After installing the new version, a reboot is recommended. For those who choose not to apply the update, it is advised to store project files securely, restrict access to trusted users, use secure communication protocols when exchanging files, encrypt project files, verify the integrity of project files before use, and harden the workstation running the software.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
10.0
exploitability
4.4
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.