« Volver al listado

CVE-2025-31286

Estado: AnalizadaCrítica (9)—

An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code.

Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inyección HTML (CWE-79) en Trend Vision One permite XSS (T1189). UI:R confirma interacción del usuario. Los impactos incluyen ejecución de código JavaScript en navegador (T1059.007) y potencial escalada de privilegios (T1068) por C:H/I:H/A:H con PR:L.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-31286",
  "cveTags": [
    {
      "tags": [
        "exclusively-hosted-service"
      ],
      "sourceIdentifier": "security@trendmicro.com"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-31286",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-02T17:54:35.458287Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@trendmicro.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@trendmicro.com",
      "affectedData": [
        {
          "vendor": "Trend Micro, Inc.",
          "product": "Trend Vision One",
          "versions": [
            {
              "status": "affected",
              "version": "NA",
              "lessThan": "NA",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-02T17:15:49.290",
  "references": [
    {
      "url": "https://success.trendmicro.com/en-US/solution/KA-0019386",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@trendmicro.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@trendmicro.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code.\r\n\r\nPlease note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de inyección HTML descubierta previamente en Trend Vision One podría haber permitido a un usuario malicioso ejecutar código arbitrario. Nota: Este problema ya se ha solucionado en el servicio backend y ya no se considera una vulnerabilidad activa. "
    }
  ],
  "lastModified": "2026-06-17T09:10:14.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:trendmicro:trend_vision_one:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "761D8AA4-4FAC-4797-84B3-20DA7F69DF8E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@trendmicro.com"
}