PT-2025-14536 · Trend Micro · Trend Vision One

Vaibhav Kumar Srivastava

·

Published

2025-04-02

·

Updated

2025-04-02

·

CVE-2025-31285

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Vision One (affected versions not specified)
Description A broken access control issue in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. This issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-31285

Affected Products

Trend Vision One