PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-3916 Schneider Electric CVE debrief

CVE-2025-3916 affects Schneider Electric EcoStruxure Power Build Rapsody and is described as a CWE-121 stack-based buffer overflow. According to the CISA CSAF advisory, an attacker can potentially trigger the issue by providing a malicious SSD project file that the end user opens. Schneider Electric states that version v2.8.2 FR contains a fix, and the advisory also recommends several file-handling and workstation-hardening mitigations.

Vendor
Schneider Electric
Product
EcoStruxure Power Build Rapsody
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-05-15
Original CVE updated
2025-05-15
Advisory published
2025-05-15
Advisory updated
2025-05-15

Who should care

Organizations using EcoStruxure Power Build Rapsody, especially teams that open or exchange SSD project files on engineering workstations. OT/ICS defenders and endpoint administrators should prioritize this if the product is installed on systems that handle untrusted project files.

Technical summary

The advisory identifies a local-impact vulnerability in Schneider Electric EcoStruxure Power Build Rapsody: a stack-based buffer overflow (CWE-121). The provided CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L, reflecting the need for user interaction and the possibility of limited confidentiality, integrity, and availability impact. The affected product scope listed in the CSAF is Schneider Electric EcoStruxure Power Build Rapsody <=v2.7.12_FR. Schneider Electric reports that v2.8.2 FR includes the fix.

Defensive priority

Medium. The score is 5.3 and exploitation requires a user to open a malicious project file, but the vendor fix is available and the vulnerable product is used in industrial engineering workflows where unsafe files can be operationally relevant.

Recommended defensive actions

  • Upgrade EcoStruxure Power Build Rapsody to v2.8.2 FR or later, per Schneider Electric.
  • Restrict SSD project files to secure storage and limit access to trusted users only.
  • Only open project files received from trusted sources.
  • Use secure communication protocols when exchanging files over the network.
  • Encrypt project files at rest and verify file integrity with hashes before use.
  • Harden the workstation running EcoStruxure Power Build Rapsody.
  • Keep control and safety networks isolated behind firewalls and minimize exposure to the Internet.
  • Apply Schneider Electric's linked security notification and industrial cybersecurity best practices before handling untrusted project files.

Evidence notes

All statements are based on the supplied CISA CSAF source item ICSA-25-135-20 and its referenced Schneider Electric security notice SEVD-2025-133-03. The source lists affected product coverage as Schneider Electric EcoStruxure Power Build Rapsody <=v2.7.12_FR, describes the flaw as a CWE-121 stack-based buffer overflow, and states that a malicious SSD project file opened by the user could potentially lead to arbitrary code execution. The advisory also lists v2.8.2 FR as the fixed version and provides file-handling and workstation-hardening mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-3916 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-3916

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-3916 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3916

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-135-20.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-135-20

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.