PT-2025-14534 · Trend Micro · Trend Vision One

Vaibhav Kumar Srivastava

·

Published

2025-04-02

·

Updated

2025-04-02

·

CVE-2025-31283

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Vision One (affected versions not specified)
Description A broken access control issue was previously discovered in the Trend Vision One User Roles component. This could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-31283

Affected Products

Trend Vision One