Impact
The vulnerability is an improper input validation flaw that allows a crafted input to cause the CAI Content Credentials application to crash, leading to a denial‑of‑service condition. The flaw is identified as CWE‑20. Because the application stops responding after the crash, confidentiality and integrity are not directly compromised, but the availability of services relying on the application is disrupted.
Affected Systems
Adobe CAI Content Credentials, versions 0.78.2, 0.7.0 and all earlier releases are impacted. No other vendors or product variants are listed as affected.
Risk and Exploitability
The CVSS score of 6.2 indicates medium overall severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation does not require user interaction. The likely attack vector is remote, where an attacker sends a specially crafted request to the vulnerable component; this inference comes from the description of an input validation flaw that can crash the application.
OpenCVE Enrichment