Broken Access Control in Trend Micro's Vision One User Roles
CVE-2025-31283
NONE
Summary
A vulnerability in the User Roles component of Trend Micro's Vision One may have enabled unauthorized privilege escalation. Following the discovery of this flaw, administrators were potentially able to create users with elevated permissions, allowing them to change account roles and access sensitive functions. This issue has been remediated on the backend, and users are encouraged to ensure they are using the latest version of the software to mitigate any potential risks.
Affected Version(s)
Trend Vision One NA
References
CVSS V3.1
Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vaibhav Kumar Srivastava of eSec Forte Technologies Pvt. Ltd