Broken Access Control in Trend Micro's Vision One User Roles
CVE-2025-31283

NONE

Key Information:

Vendor
CVE Published:
2 April 2025

Summary

A vulnerability in the User Roles component of Trend Micro's Vision One may have enabled unauthorized privilege escalation. Following the discovery of this flaw, administrators were potentially able to create users with elevated permissions, allowing them to change account roles and access sensitive functions. This issue has been remediated on the backend, and users are encouraged to ensure they are using the latest version of the software to mitigate any potential risks.

Affected Version(s)

Trend Vision One NA

References

CVSS V3.1

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vaibhav Kumar Srivastava of eSec Forte Technologies Pvt. Ltd
.