PT-2025-14533 · Trend Micro · Trend Vision One

Vaibhav Kumar Srivastava

·

Published

2025-04-02

·

Updated

2025-04-02

·

CVE-2025-31282

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Vision One (affected versions not specified)
Description A broken access control issue in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-31282

Affected Products

Trend Vision One