Impact
CAI Content Credentials contains an integer underflow flaw that is triggered when the application processes certain numeric inputs. The underflow causes an internal counter to wrap around, which results in a legitimate runtime error that terminates the process. The consequence is an application denial‑of-service; there is no need for any additional user interaction beyond supplying the crafted input.
Affected Systems
Adobe’s Content Credentials Command‑Line Tool, JS SDK, and Rust SDK are impacted. No explicit vulnerable version range was provided, so any release prior to the fix released in the advisory should be treated as at risk.
Risk and Exploitability
The CVSS score of 6.2 classifies this vulnerability as medium severity, while the EPSS score of < 1 % indicates that exploitation is unlikely. The issue is not listed in CISA’s KEV catalog. The likely attack vector is remote exploitation via malicious input provided to the vulnerable product, inferred from the description that no user interaction is required; repeated exploit attempts could repeatedly crash the product and cause downtime.
OpenCVE Enrichment