Impact
The vulnerability is an improper input validation flaw in Adobe CAI Content Credentials versions 0.78.2, 0.7.0, and earlier. Attackers can supply crafted input that causes the application to crash, resulting in a denial-of-service. No user interaction is required, so the attack can be carried out remotely. The flaw does not enable bypassing authentication or accessing data, but it disrupts availability.
Affected Systems
Affected product is Adobe CAI Content Credentials, a component of Adobe’s Content Authenticity SDK. Versions 0.78.2, 0.7.0, and all earlier releases are vulnerable. Organizations that deploy the SDK should verify the version in use and evaluate any risk of downtime.
Risk and Exploitability
The CVSS score is 6.2, placing it in the medium severity range. EPSS is not available, but lack of user interaction and exposed input imply a moderate exploitation probability. The vulnerability is not listed in CISA KEV, which indicates no known widespread exploitation. Attackers could trigger the denial-of-service by sending specially crafted requests at any time, so the risk is highest for services that expose the vulnerable component to the network.
OpenCVE Enrichment