CVE-2025-31284
CVE-2025-31284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.6EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
02 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges.
Please note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Affected products
Trend Micro, Inc. · Trend Vision OneWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →